{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:45a66a16-b316-481a-8dbe-be9a6cc25fd4",
  "version": 1,
  "metadata": {
    "timestamp": "2026-10-09T15:07:20+00:00",
    "tools": {
      "components": [
        {
          "type": "application",
          "manufacturer": {
            "name": "Aqua Security Software Ltd."
          },
          "group": "aquasecurity",
          "name": "trivy",
          "version": "0.69.3"
        }
      ]
    },
    "component": {
      "bom-ref": "5c1367db-fb03-4cb5-b381-500cc49d5e1d",
      "type": "application",
      "supplier": {
        "name": "Confluent"
      },
      "name": "confluent-ce-kafka-http-server",
      "version": "7.8.11-1",
      "properties": [
        {
          "name": "aquasecurity:trivy:SchemaVersion",
          "value": "2"
        }
      ]
    }
  },
  "components": [],
  "dependencies": [],
  "vulnerabilities": [
    {
      "id": "CVE-2024-6763",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 3.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1286
      ],
      "description": "Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing.\n\nThe HttpURI class does insufficient validation on the authority segment of a URI.  However the behaviour of HttpURI\n differs from the common browsers in how it handles a URI that would be \nconsidered invalid if fully validated against the RRC.  Specifically HttpURI\n and the browser may differ on the value of the host extracted from an \ninvalid URI and thus a combination of Jetty and a vulnerable browser may\n be vulnerable to a open redirect attack or to a SSRF attack if the URI \nis used after passing validation checks.",
      "recommendation": "Upgrade org.eclipse.jetty:jetty-http to version 12.0.12",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-6763"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-6763"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2024-6763"
        },
        {
          "url": "https://github.com/advisories/GHSA-qh8g-58pp-2wxh"
        },
        {
          "url": "https://github.com/jetty/jetty.project"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/12012"
        },
        {
          "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxh"
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignement/-/issues/25"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6763"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250306-0005"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250306-0005/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-6763"
        }
      ],
      "published": "2024-10-14T16:15:04+00:00",
      "updated": "2026-06-17T08:18:39+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-http@9.4.63",
          "versions": [
            {
              "version": "9.4.63",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ea178dad-aedd-4391-a8c5-926702a8a770/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:169aad26-1f9c-4ac9-808a-8fc98a9d2c26/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:0f38e865-ae5c-46fc-9877-feae7da2ec81/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:26d3ab9a-48d7-467f-b70e-74852e525d1e/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This vulnerability is not exploitable in the context of Confluent Platform as URIs are not used to pass sensitive information. "
      }
    },
    {
      "id": "CVE-2026-106449",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        674
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-106449"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-106449"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-106449"
        },
        {
          "url": "https://github.com/advisories/GHSA-343h-94h5-c4wr"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-106449"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-106449"
        }
      ],
      "published": "2026-10-06T20:17:26+00:00",
      "updated": "2026-10-07T17:16:47+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.11.1",
          "versions": [
            {
              "version": "1.11.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ea178dad-aedd-4391-a8c5-926702a8a770/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:97b06811-8109-4e82-a9b9-7b7a95a4067a/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:169aad26-1f9c-4ac9-808a-8fc98a9d2c26/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:0f38e865-ae5c-46fc-9877-feae7da2ec81/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:d3780ff8-2e60-4f8f-b121-aa1c09acbd1f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:80f0b82b-a68c-4721-9562-b85a1e937d3d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:26d3ab9a-48d7-467f-b70e-74852e525d1e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-106450",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        770
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode allows attacker-controlled streams containing many minimal empty frames to trigger roughly 8 MiB of allocation for every 11 input bytes. The stream produces no decompressed output while consuming CPU and garbage-collection time, so decompressed-size limits do not mitigate the issue; readSingleFrame mode is not affected. This issue is fixed in version 1.11.4.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-106450"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-106450"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-106450"
        },
        {
          "url": "https://github.com/advisories/GHSA-gm45-99xc-r7wv"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-106450"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-106450"
        }
      ],
      "published": "2026-10-06T20:17:27+00:00",
      "updated": "2026-10-09T02:16:59+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.11.1",
          "versions": [
            {
              "version": "1.11.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ea178dad-aedd-4391-a8c5-926702a8a770/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:97b06811-8109-4e82-a9b9-7b7a95a4067a/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:169aad26-1f9c-4ac9-808a-8fc98a9d2c26/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:0f38e865-ae5c-46fc-9877-feae7da2ec81/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:d3780ff8-2e60-4f8f-b121-aa1c09acbd1f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:80f0b82b-a68c-4721-9562-b85a1e937d3d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:26d3ab9a-48d7-467f-b70e-74852e525d1e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-106451",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        367,
        377
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. Successful exploitation depends on shared-directory permissions, host protections, and winning the race, and can execute native code as the victim; hardened systems may instead cause library loading to fail and fall back to Java implementations. Configurations using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This issue is fixed in version 1.11.4.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-106451"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-106451"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-106451"
        },
        {
          "url": "https://github.com/advisories/GHSA-mcr4-qmvw-px4g"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-106451"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-106451"
        }
      ],
      "published": "2026-10-06T20:17:27+00:00",
      "updated": "2026-10-07T19:17:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.11.1",
          "versions": [
            {
              "version": "1.11.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ea178dad-aedd-4391-a8c5-926702a8a770/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:97b06811-8109-4e82-a9b9-7b7a95a4067a/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:169aad26-1f9c-4ac9-808a-8fc98a9d2c26/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:0f38e865-ae5c-46fc-9877-feae7da2ec81/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:d3780ff8-2e60-4f8f-b121-aa1c09acbd1f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:80f0b82b-a68c-4721-9562-b85a1e937d3d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:26d3ab9a-48d7-467f-b70e-74852e525d1e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-106452",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        789
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only stream to request a near-2 GiB allocation and exhaust the JVM heap. Canonical writers emit raw blocks when compression is not smaller than the original block, but vulnerable readers accept non-canonical oversized compressed blocks. This issue is fixed in version 1.11.2.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-106452"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-106452"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-106452"
        },
        {
          "url": "https://github.com/advisories/GHSA-4v53-57pg-c464"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-106452"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-106452"
        }
      ],
      "published": "2026-10-06T20:17:27+00:00",
      "updated": "2026-10-07T13:58:29+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.11.1",
          "versions": [
            {
              "version": "1.11.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ea178dad-aedd-4391-a8c5-926702a8a770/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:97b06811-8109-4e82-a9b9-7b7a95a4067a/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:169aad26-1f9c-4ac9-808a-8fc98a9d2c26/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:0f38e865-ae5c-46fc-9877-feae7da2ec81/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:d3780ff8-2e60-4f8f-b121-aa1c09acbd1f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:80f0b82b-a68c-4721-9562-b85a1e937d3d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:26d3ab9a-48d7-467f-b70e-74852e525d1e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-106453",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        789
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied input whose header declares a large output size to request up to approximately 2 GiB and exhaust the JVM heap. Convenience overloads backed by LZ4FastDecompressor or LZ4SafeDecompressor allocate the untrusted size, while overloads that write to a caller-provided destination buffer are not affected because the caller controls the destination size. This issue is fixed in version 1.11.2.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-106453"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-106453"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-106453"
        },
        {
          "url": "https://github.com/advisories/GHSA-6cx8-rjf8-pr8g"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-106453"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-106453"
        }
      ],
      "published": "2026-10-06T20:17:27+00:00",
      "updated": "2026-10-07T17:16:48+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.11.1",
          "versions": [
            {
              "version": "1.11.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ea178dad-aedd-4391-a8c5-926702a8a770/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:97b06811-8109-4e82-a9b9-7b7a95a4067a/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:169aad26-1f9c-4ac9-808a-8fc98a9d2c26/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:0f38e865-ae5c-46fc-9877-feae7da2ec81/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:d3780ff8-2e60-4f8f-b121-aa1c09acbd1f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:80f0b82b-a68c-4721-9562-b85a1e937d3d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:26d3ab9a-48d7-467f-b70e-74852e525d1e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-19032",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        470,
        610
      ],
      "description": "jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader<FileSystemProvider> and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted JSON should be avoided regardless of version.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.10, 2.21.6, 2.22.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-19032"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-19032"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-19032"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/6129"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19032"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19032"
        }
      ],
      "published": "2026-09-01T04:18:00+00:00",
      "updated": "2026-09-08T19:29:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9",
          "versions": [
            {
              "version": "2.18.9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ea178dad-aedd-4391-a8c5-926702a8a770/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:a8faf7d5-c88e-46f9-b915-1596f118b6c7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:169aad26-1f9c-4ac9-808a-8fc98a9d2c26/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0f38e865-ae5c-46fc-9877-feae7da2ec81/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:d3780ff8-2e60-4f8f-b121-aa1c09acbd1f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:f0a28f27-621a-4279-8fe1-a96bc48f31bc/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:26d3ab9a-48d7-467f-b70e-74852e525d1e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-68497",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400,
        1333
      ],
      "description": "jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.10, 2.21.6, 2.22.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-68497"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-68497"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-68497"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/6127"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-68497.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-77648.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68497"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68497"
        }
      ],
      "published": "2026-09-11T16:17:39+00:00",
      "updated": "2026-09-18T19:34:36+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9",
          "versions": [
            {
              "version": "2.18.9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ea178dad-aedd-4391-a8c5-926702a8a770/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:a8faf7d5-c88e-46f9-b915-1596f118b6c7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:169aad26-1f9c-4ac9-808a-8fc98a9d2c26/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0f38e865-ae5c-46fc-9877-feae7da2ec81/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:d3780ff8-2e60-4f8f-b121-aa1c09acbd1f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:f0a28f27-621a-4279-8fe1-a96bc48f31bc/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:26d3ab9a-48d7-467f-b70e-74852e525d1e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The vulnerable jackson-databind version is present fleet-wide, but no CP repo's own code declares a javax.xml.datatype.Duration or XMLGregorianCalendar field, so the vulnerable deserialization sink cannot be reached."
      }
    },
    {
      "id": "CVE-2026-83557",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        502,
        915
      ],
      "description": "DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of \"unsafe base types\", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.10, 2.21.6, 2.22.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-83557"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-83557"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-83557"
        },
        {
          "url": "https://getsafety.com/vulnerabilities/SFTY-20260901-46895/CVE-2026-83557"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/6156"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/6155"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83557"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-83557"
        }
      ],
      "published": "2026-09-01T15:17:37+00:00",
      "updated": "2026-09-08T19:29:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9",
          "versions": [
            {
              "version": "2.18.9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ea178dad-aedd-4391-a8c5-926702a8a770/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:a8faf7d5-c88e-46f9-b915-1596f118b6c7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:169aad26-1f9c-4ac9-808a-8fc98a9d2c26/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0f38e865-ae5c-46fc-9877-feae7da2ec81/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:d3780ff8-2e60-4f8f-b121-aa1c09acbd1f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:f0a28f27-621a-4279-8fe1-a96bc48f31bc/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:26d3ab9a-48d7-467f-b70e-74852e525d1e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-89407",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        1333
      ],
      "description": "NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run.\u00a0\n\n\n\nMatching cost therefore grows with the square of the input length.\u00a0\n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float).\u00a0\n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex.\u00a0\n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool.\u00a0\n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected.\u00a0\n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-core to version 2.18.11, 2.21.7, 2.22.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89407"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89407"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-89407"
        },
        {
          "url": "https://getsafety.com/vulnerabilities/SFTY-20260922-89449/CVE-2026-89407"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/issues/1649"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/pull/1650"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/pull/1701"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89407"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89407"
        }
      ],
      "published": "2026-09-22T15:17:21+00:00",
      "updated": "2026-09-22T20:00:03+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9",
          "versions": [
            {
              "version": "2.18.9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ea178dad-aedd-4391-a8c5-926702a8a770/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:a8faf7d5-c88e-46f9-b915-1596f118b6c7/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:97b06811-8109-4e82-a9b9-7b7a95a4067a/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:169aad26-1f9c-4ac9-808a-8fc98a9d2c26/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:0f38e865-ae5c-46fc-9877-feae7da2ec81/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:d3780ff8-2e60-4f8f-b121-aa1c09acbd1f/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:f0a28f27-621a-4279-8fe1-a96bc48f31bc/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:26d3ab9a-48d7-467f-b70e-74852e525d1e/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-89425",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-core to version 2.21.7, 2.22.3, 2.18.11",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89425"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89425"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-89425"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/pull/1698"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89425"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89425"
        }
      ],
      "published": "2026-09-23T03:17:04+00:00",
      "updated": "2026-09-24T20:43:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9",
          "versions": [
            {
              "version": "2.18.9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ea178dad-aedd-4391-a8c5-926702a8a770/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:a8faf7d5-c88e-46f9-b915-1596f118b6c7/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:97b06811-8109-4e82-a9b9-7b7a95a4067a/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:169aad26-1f9c-4ac9-808a-8fc98a9d2c26/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:0f38e865-ae5c-46fc-9877-feae7da2ec81/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:d3780ff8-2e60-4f8f-b121-aa1c09acbd1f/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:f0a28f27-621a-4279-8fe1-a96bc48f31bc/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:26d3ab9a-48d7-467f-b70e-74852e525d1e/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-91776",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.11, 2.21.7, 2.22.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-91776"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-91776"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-91776"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/6203"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-91776"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-91776"
        }
      ],
      "published": "2026-09-23T03:17:04+00:00",
      "updated": "2026-09-24T20:43:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9",
          "versions": [
            {
              "version": "2.18.9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ea178dad-aedd-4391-a8c5-926702a8a770/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:a8faf7d5-c88e-46f9-b915-1596f118b6c7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:169aad26-1f9c-4ac9-808a-8fc98a9d2c26/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0f38e865-ae5c-46fc-9877-feae7da2ec81/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:d3780ff8-2e60-4f8f-b121-aa1c09acbd1f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:f0a28f27-621a-4279-8fe1-a96bc48f31bc/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:26d3ab9a-48d7-467f-b70e-74852e525d1e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-91777",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.21.7, 2.18.11, 2.22.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-91777"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-91777"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-91777"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/6204"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/6204"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-91777"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-91777"
        }
      ],
      "published": "2026-09-23T03:17:04+00:00",
      "updated": "2026-09-24T20:43:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9",
          "versions": [
            {
              "version": "2.18.9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ea178dad-aedd-4391-a8c5-926702a8a770/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:a8faf7d5-c88e-46f9-b915-1596f118b6c7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:169aad26-1f9c-4ac9-808a-8fc98a9d2c26/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0f38e865-ae5c-46fc-9877-feae7da2ec81/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:d3780ff8-2e60-4f8f-b121-aa1c09acbd1f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:f0a28f27-621a-4279-8fe1-a96bc48f31bc/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:26d3ab9a-48d7-467f-b70e-74852e525d1e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-56740",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit the number of environment variables a client may inject via the Telnet NEW-ENVIRON option, and TelnetIO.readNEVariables() in TelnetIO.java:1127-1180 stores each variable pair in a HashMap held by ConnectionData, allowing an unauthenticated attacker to flood unique variable pairs before the terminating IAC SE byte and exhaust JVM heap memory with an OutOfMemoryError. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.",
      "recommendation": "Upgrade org.jline:jline-remote-telnet to version 4.2.1, 4.0.16, 3.30.14",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56740"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56740"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-56740"
        },
        {
          "url": "https://github.com/advisories/GHSA-47qp-hqvx-6r3f"
        },
        {
          "url": "https://github.com/jline/jline3"
        },
        {
          "url": "https://github.com/jline/jline3/commit/0389f0ee6d0375901b602671ad5dafd4d1d4ee09"
        },
        {
          "url": "https://github.com/jline/jline3/commit/4ee3a73849ffb9a85ec748e4e8cd8f6d81f84f40"
        },
        {
          "url": "https://github.com/jline/jline3/commit/934f09e6128cee33c2b13d42b6e859c1ee2d194b"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2000"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2001"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.0.16"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.2.1"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/jline-3.30.14"
        },
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-47qp-hqvx-6r3f"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56740"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56740"
        }
      ],
      "published": "2026-07-17T22:17:57+00:00",
      "updated": "2026-08-18T15:23:04+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.25.1",
          "versions": [
            {
              "version": "3.25.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. No CP repository constructs or starts a JLine Telnet server anywhere, so the vulnerable NEW-ENVIRON variable-flooding sink in TelnetIO is never reachable."
      }
    },
    {
      "id": "CVE-2026-56741",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS option, and TelnetIO.handleNAWS() in TelnetIO.java:856-879 reads client-supplied width and height as 16-bit unsigned integers and passes values such as 65535x65535 to setTerminalGeometry(), allowing an unauthenticated remote attacker to repeatedly alternate values and trigger continuous expensive rendering work that causes CPU exhaustion and denial of service. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.",
      "recommendation": "Upgrade org.jline:jline-remote-telnet to version 4.2.1, 4.0.16, 3.30.14",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56741"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56741"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-56741"
        },
        {
          "url": "https://github.com/advisories/GHSA-2r2c-cx56-8933"
        },
        {
          "url": "https://github.com/jline/jline3"
        },
        {
          "url": "https://github.com/jline/jline3/commit/3ea9cad8699714dc072fade29d36be0d1e23d708"
        },
        {
          "url": "https://github.com/jline/jline3/commit/733eb353dca7b0ea0252e724445b6defa29c393e"
        },
        {
          "url": "https://github.com/jline/jline3/commit/86b7ba7801988aadb1a67555629522a71d603bd3"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2000"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.0.16"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.2.1"
        },
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-2r2c-cx56-8933"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56741"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56741"
        }
      ],
      "published": "2026-07-17T22:17:57+00:00",
      "updated": "2026-08-18T15:17:51+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.25.1",
          "versions": [
            {
              "version": "3.25.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. No CP repository constructs or starts a JLine Telnet server anywhere, so the vulnerable NAWS terminal-geometry sink in TelnetIO is never reachable."
      }
    },
    {
      "id": "CVE-2026-75595",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        754
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHello whose handshake header spans records can cause an IndexOutOfBoundsException and invoke select(ctx, null). This selects the default SslContext instead of the SNI-specific context. In deployments where per-SNI clientAuth=REQUIRE is the sole mutual TLS gate, the default SslContext uses clientAuth=NONE or clientAuth=OPTIONAL, and no application-layer certificate verification exists, an unauthenticated remote attacker can bypass the protected route's mutual TLS requirement. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.",
      "recommendation": "Upgrade io.netty:netty-handler to version 4.2.17.Final, 4.1.137.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-75595"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-75595"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-75595"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7"
        },
        {
          "url": "https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961"
        },
        {
          "url": "https://github.com/netty/netty/pull/17213"
        },
        {
          "url": "https://github.com/netty/netty/pull/17217"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.137.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-c4c3-7fpv-j4q5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75595"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75595"
        }
      ],
      "published": "2026-08-19T21:17:37+00:00",
      "updated": "2026-09-22T19:33:26+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.136.Final",
          "versions": [
            {
              "version": "4.1.136.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The vulnerable Netty SslClientHelloHandler is present only as a transitive outbound-client dependency across CP repos; no in-scope repo wires it into a per-SNI, per-clientAuth-varying inbound TLS listener, so the bypass mechanism cannot fire."
      }
    },
    {
      "id": "CVE-2026-75596",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        407
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/main/java/io/netty/handler/ssl/SslClientHelloHandler.java at io.netty.handler.ssl.SslClientHelloHandler#decode, where handshakeBuffer.clear() and writeBytes() recopy all previously received body bytes for every additional TLS record. An unauthenticated remote peer can advertise a large ClientHello and deliver its body in thousands of tiny records, causing quadratic CPU work on the event loop before the TLS handshake completes and degrading TLS handling for other clients. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.",
      "recommendation": "Upgrade io.netty:netty-handler to version 4.2.17.Final, 4.1.137.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-75596"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-75596"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7"
        },
        {
          "url": "https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961"
        },
        {
          "url": "https://github.com/netty/netty/pull/17213"
        },
        {
          "url": "https://github.com/netty/netty/pull/17217"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.137.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75596"
        }
      ],
      "published": "2026-08-19T21:17:37+00:00",
      "updated": "2026-09-22T19:28:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.136.Final",
          "versions": [
            {
              "version": "4.1.136.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-77420",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        1333
      ],
      "description": "JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPatterns(String patterns, String line) in reader/src/main/java/org/jline/reader/impl/history/DefaultHistory.java converts the HISTORY_IGNORE configuration value into a Java regular expression while escaping only part of its syntax, allowing other regex metacharacters to reach the backtracking engine. An attacker who can control application or user configuration can supply a nested-quantifier expression that is reevaluated whenever a command is added to history, consuming excessive CPU and indefinitely blocking the reader thread. This issue is fixed in versions 3.30.15 and 4.3.1.",
      "recommendation": "Upgrade org.jline:jline-reader to version 4.3.1, 3.30.15",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-77420"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-77420"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-77420"
        },
        {
          "url": "https://github.com/jline/jline3"
        },
        {
          "url": "https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541"
        },
        {
          "url": "https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2012"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2018"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.3.1"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/jline-3.30.15"
        },
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-5q95-hrpc-m3w3"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77420"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77420"
        }
      ],
      "published": "2026-09-23T19:19:15+00:00",
      "updated": "2026-09-30T19:38:27+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.jline/jline-reader@3.25.1",
          "versions": [
            {
              "version": "3.25.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.jline/jline-reader@3.30.14",
          "versions": [
            {
              "version": "3.30.14",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/org.jline/jline-reader@3.25.1"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.jline/jline-reader@3.30.14"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.jline/jline-reader@3.25.1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.jline/jline-reader@3.30.14"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/org.jline/jline-reader@3.25.1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/org.jline/jline-reader@3.25.1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/org.jline/jline-reader@3.25.1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.jline/jline-reader@3.25.1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.jline/jline-reader@3.25.1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.jline/jline-reader@3.25.1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.jline/jline-reader@3.25.1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.jline/jline-reader@3.25.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/org.jline/jline-reader@3.25.1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/org.jline/jline-reader@3.25.1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.jline/jline-reader@3.25.1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.jline/jline-reader@3.30.14"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.jline/jline-reader@3.30.14"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.jline/jline-reader@3.25.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.jline/jline-reader@3.30.14"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.jline/jline-reader@3.25.1"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.jline/jline-reader@3.30.14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-77421",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        1333
      ],
      "description": "JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's regex search mode passes a user-controlled search term from doSearch(String text) in builtins/src/main/java/org/jline/builtins/Nano.java to Java's backtracking regular expression engine without a timeout or backtracking bound. A nested-quantifier expression evaluated against non-matching buffer content can consume excessive CPU and indefinitely block the editor session thread, and remote multi-user deployments can lose a worker thread for each affected session. This issue is fixed in versions 3.30.15 and 4.3.1.",
      "recommendation": "Upgrade org.jline:jline-builtins to version 4.3.1, 3.30.15",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-77421"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-77421"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-77421"
        },
        {
          "url": "https://github.com/jline/jline3"
        },
        {
          "url": "https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541"
        },
        {
          "url": "https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2012"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2018"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.3.1"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/jline-3.30.15"
        },
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-ph9c-7hw9-vhhw"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77421"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77421"
        }
      ],
      "published": "2026-09-23T19:19:15+00:00",
      "updated": "2026-09-30T16:44:39+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.jline/jline-builtins@3.25.1",
          "versions": [
            {
              "version": "3.25.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.jline/jline-builtins@3.30.14",
          "versions": [
            {
              "version": "3.30.14",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-77422",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        1333
      ],
      "description": "JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command in builtins/src/main/java/org/jline/builtins/PosixCommands.java accepts a user-controlled regular expression in grep(...) and, unless line-regexp mode is used, automatically adds a dot-star prefix and suffix before compiling it with Java's backtracking regular expression engine. The wrapping expands the backtracking search space, so a short nested-quantifier expression evaluated against non-matching input can consume excessive CPU and indefinitely block a command worker, including in remotely exposed shell sessions. This issue is fixed in versions 3.30.15 and 4.3.1.",
      "recommendation": "Upgrade org.jline:jline-builtins to version 4.3.1, 3.30.15",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-77422"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-77422"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-77422"
        },
        {
          "url": "https://github.com/jline/jline3"
        },
        {
          "url": "https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541"
        },
        {
          "url": "https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2012"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2018"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.3.1"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/jline-3.30.15"
        },
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-r2xf-8xr9-62gw"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77422"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77422"
        }
      ],
      "published": "2026-09-23T19:19:15+00:00",
      "updated": "2026-09-30T16:44:39+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.jline/jline-builtins@3.25.1",
          "versions": [
            {
              "version": "3.25.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.jline/jline-builtins@3.30.14",
          "versions": [
            {
              "version": "3.30.14",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:f31debbb-98b7-4cec-9a58-402f26906d6f/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.jline/jline-builtins@3.25.1"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-107226",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "description": "### Impact\nThe cookie store ignores the scheme a `Set-Cookie` arrived on. draft-ietf-httpbis-rfc6265bis-22 (approved to obsolete RFC 6265, in the RFC Editor queue) Section 5.7 requires a user agent to ignore a cookie with the `Secure` attribute unless it arrived over a secure connection (step 13), and to ignore a non-Secure cookie from an insecure connection when it would overlay a Secure cookie the store already holds (step 16). Neither rule is implemented. The only `Secure` handling is on retrieval, where a Secure cookie is not sent over plaintext.\n\nSo anyone who can answer a plaintext request to a site can set, replace or delete the site's `Secure` cookies, and the next HTTPS request carries the attacker's value back inside TLS:\n\n```\nhttp://example.com   ->  Set-Cookie: SID=attacker-value; Secure; Path=/\nhttps://example.com  ->  Cookie: SID=attacker-value\n```\n\nThis does not need an attacker on the network path. A plaintext host under the same site reaches the HTTPS one by setting a domain cookie:\n\n```\nhttp://insecure.example.com  ->  Set-Cookie: SID=attacker-value; Secure; Domain=example.com; Path=/\nhttps://bank.example.com     ->  Cookie: SID=attacker-value\n```\n\nA plaintext `Set-Cookie` of the same name, domain and path overwrites a Secure cookie, and one with `Max-Age=0` deletes it. Depending on what the application does with the cookie, this is session fixation into the HTTPS session, an overwritten CSRF token, or the removal of a cookie the site relies on. Unlike GHSA-qjr7-w8pj-pmv9, which can only add a cookie, this replaces or deletes one, hence Integrity: High; the harm lands on the HTTPS site, hence Scope: Changed.\n\n### Affected versions\n* 3.x: up to and including 3.0.13\n* 2.x: from 2.1.0, when the cookie store was introduced, up to and including 2.16.1\n\n### Patches\nFixed in 3.0.14 on the 3.x line. A cookie with the `Secure` attribute is ignored unless the request was secure, and a non-Secure cookie from a request that did not use TLS is ignored when it would overlay a Secure cookie of the same name whose path its own path falls under. A plaintext response can therefore no longer plant, overwrite or delete a `Secure` cookie.\n\nWhen several cookies of one name match a request, the client sends only the first, so the order in which the store returns them decides which one is used. That order is now: on a secure request, cookies received in a secure context (HTTPS, WSS or plaintext loopback) first; then the request host's own cookies before cookies set for a parent domain; then, within one host, longer paths first. A plaintext attacker cannot outrank a cookie the site set over HTTPS by ordering or padding its own cookies, or by setting one before the site sets its own.\n\nPlaintext requests to `localhost`, or to an address literal that is a loopback address, count as secure, so a development server that sets `Secure` cookies over `http://localhost` gets them back. This is limited to the cookies such a server set itself: a `Secure` cookie that arrived over HTTPS is never sent over plaintext, loopback included, and a plaintext loopback port cannot overlay it. Numeric spellings that are not address literals, such as `127.0.0.256`, and names under `localhost` are not treated as loopback, because the client resolves them as names.\n\nThe 2.x line is end of life and will not receive a fix. Upgrade to 3.0.14.\n\n### Workarounds\nDo not share one `CookieStore` between plaintext and HTTPS origins that are not mutually trusted, including hosts under the same site. Disabling the cookie store also avoids it.\n\n### Details\n`ThreadSafeCookieStore.add(Uri, Cookie)` reduces the request to its host and path before storing, so the scheme never reaches the code that decides whether to keep a cookie. `get(Uri)` does read it, but only to leave `Secure` cookies out of plaintext requests.\n\nA narrower form survives the two storage rules on their own. The step 16 path test is one-way by design, so a plaintext `SID` for `Path=/` is legitimately stored beside a Secure `SID` for `Path=/account`, and both match a request under `/account`. The store returned matching cookies in hash order, and the client keeps only the first cookie of each name when it builds the request (`RequestBuilderBase.addCookieIfUnset`), so an attacker could decide which one was sent, for example by padding one plaintext response with filler cookies. The ordering described above closes it.\n\nThe fix does not stop an HTTPS host under the same site from setting a domain cookie for a name the request host never sets itself. Only a `__Host-` cookie name prefix prevents that, and the client does not enforce cookie name prefixes.\n\n### Attribution\n\nAI-assisted tools were used to support discovery and analysis.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.14",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107226"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/6ec7ee45034d154f502852a962d2891746fb82c1"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-p2jm-6hj6-9rjg"
        }
      ],
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-107227",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        409
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded when compression is enabled. The inbound pipeline aggregates compressed frames before WebSocketClientCompressionHandler inflates them, so webSocketMaxFrameSize and webSocketMaxBufferSize do not bound decompressed output. A malicious WebSocket peer can send a small compressed message that expands to a very large Netty buffer and exhausts JVM heap. This issue is fixed in version 3.0.14.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.14",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107227"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-107227"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-x8v2-478q-2hvg"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107227"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-107227"
        }
      ],
      "published": "2026-10-07T21:17:14+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-107228",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        287
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user's request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. This issue is fixed in version 3.0.14.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.14",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107228"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-2jwh-9rmr-j4xf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107228"
        }
      ],
      "published": "2026-10-07T21:17:14+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-107230",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        346,
        863
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 3.0.14, connection-pool partitioning still omits identity-defining fields for Kerberos, SPNEGO, NTLM, and authenticated proxy connections. Logins without a configured principal, proxy realms, identities sharing a user name, and SOCKS or CONNECT proxy logins can reuse a socket authenticated as a different identity. A later request is then executed under the first identity and can expose that identity's data or authority to another caller. In the affected execution path, SpnegoEngine, NTLM, Kerberos, SPNEGO, SOCKS, and CONNECT control or expose the vulnerable behavior. This issue is fixed in version 3.0.14.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.14",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107230"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-107230"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-v2j5-22fr-j62r"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107230"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-107230"
        }
      ],
      "published": "2026-10-07T22:17:03+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-107231",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        319,
        522,
        757
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, Realm.Builder treats a Digest challenge that yields no usable nonce as a Basic challenge. A malicious origin or proxy can label a challenge Digest while omitting or emptying the nonce, causing the client to resend the username and password using reversible Basic authentication. Both origin and proxy challenge parsers are affected. This issue is fixed in versions 3.0.13 and 2.16.1.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.13, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107231"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-107231"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/8376866aa9b5a7653ad19db9d472692f875caa83"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/c8d639bf6ac341d377d610a93570bcd15565f1a6"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rqf5-2wxv-rjf4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107231"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-107231"
        }
      ],
      "published": "2026-10-07T22:17:03+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-107280",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [],
      "cwes": [
        1275
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13  and 2.16.1, ThreadSafeCookieStore validates Domain attributes with domain matching but does not reject public suffixes. A host beneath a suffix such as co.uk can set a cookie for that suffix, after which the shared cookie store sends it to unrelated hosts under the suffix. This can inject or overwrite session-relevant cookie values across origins. This issue is fixed in versions 3.0.13 and 2.16.1.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.13, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107280"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/330267895fe0bdb41bbd027ea6b151d38ee7c23d"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/d1f0ccec417092098d40242fee7dfac84bb3c21f"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-f9m8-cv68-674w"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107280"
        }
      ],
      "published": "2026-10-07T22:17:03+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-107282",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [],
      "cwes": [
        319,
        441,
        522
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13  and 2.16.1, cross-host request replay updates the current request but leaves the target request and related proxy context pointing at the original origin. Connection-pool selection, CONNECT handling, realm selection, and TLS setup can consequently send the original host's path, Host header, Authorization credentials, or plaintext request to the replay destination. Documented ResponseFilter failover and retry paths can trigger the replay. This issue is fixed in versions 3.0.13 and 2.16.1.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.13, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107282"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/15b254514a411623e5f1d8c99ea79c0f82f8a466"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/bbc31aed3b044f9f7a126cf689a8c8d7ad2ae1cb"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-jmqq-x5g9-9p2w"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107282"
        }
      ],
      "published": "2026-10-07T22:17:04+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-107283",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        338
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12  and 2.16.1, Realm.Builder generates the HTTP Digest client nonce with ThreadLocalRandom rather than a cryptographically secure random source. Digest relies on an unpredictable cnonce to resist chosen-plaintext and credential precomputation attacks, so an observer able to infer generator state can reduce the protection of the authentication exchange. This issue is fixed in versions 3.0.12 and 2.16.1.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.12, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107283"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/dca2d90db87f0144ea893a6858dca13c426d06b6"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/e1f5fc88fe211d3f64032c33b91093ba3d5e793d"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-mfj3-87qq-382v"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107283"
        }
      ],
      "published": "2026-10-07T22:17:04+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-107285",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        319,
        522
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through CONNECT, but NettyRequestFactory.newNettyRequest and requestUri decide whether to attach proxy authentication and an absolute-form target only from whether the URI is secure. Because ws is not marked secure, the tunneled WebSocket upgrade sent to the origin includes the proxy's Proxy-Authorization value. Basic credentials are directly recoverable and Digest responses can be replayed or cracked offline. This issue is fixed in versions 3.0.12 and 2.16.1.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.12, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107285"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/6e9cb75a9b7259353f983fc90ca28b1da3742e18"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/c4feab0f7f86d61505a48e40d383c8a375a22e18"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-3wp9-xfwm-rjjf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107285"
        }
      ],
      "published": "2026-10-07T22:17:04+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-55688",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1275
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In versions from 2.0.0 prior to 2.16.0 and from 3.0.0.Beta1 prior to 3.0.11, ThreadSafeCookieStore stored a cookie under the value of its Domain attribute without verifying that the responding host is allowed to set a cookie for that domain, leading to a cookie tossing / cookie injection issue. A host the client connects to can therefore plant a cookie scoped to an unrelated domain, and the client will then send that cookie on later requests to that domain. Applications that use a single AsyncHttpClient instance - and thus the default, shared CookieStore - to reach both an attacker-influenced host and a trusted host are impacted. This issue has been fixed in versions 2.16.0 and 3.0.11.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.11, 2.16.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55688"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55688"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-55688"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/8e4069cf3c92abe099db5fb13378ac2fe9e1fd3b"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/e6955c1e3951cf80e286981d064f6c926ce33f47"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/pull/2196"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/pull/2199"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.0"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.11"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-m452-q8c9-rg2f"
        },
        {
          "url": "https://github.com/advisories/GHSA-m452-q8c9-rg2f"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/08/msg00011.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55688"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8655-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55688"
        }
      ],
      "published": "2026-07-01T20:17:11+00:00",
      "updated": "2026-08-06T22:17:52+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in Confluent Platform because async-http-client is used only for a single, fixed, internal Druid telemetry endpoint; no mixed-trust multi-host scenario exists for this CVE's cookie-tossing mechanism to apply. This issue will be addressed in an upcoming release when an updated package is available from the vendor."
      }
    },
    {
      "id": "CVE-2026-59903",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "cwes": [
        524
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, allowing a caching proxy or CDN to reuse authenticated responses across users and disclose sensitive information. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.17.Final, 4.1.137.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59903"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59903"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-59903"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/pull/17213"
        },
        {
          "url": "https://github.com/netty/netty/pull/17217"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.137.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59903"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59903"
        }
      ],
      "published": "2026-08-17T18:17:36+00:00",
      "updated": "2026-09-23T15:21:27+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.136.Final",
          "versions": [
            {
              "version": "4.1.136.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in Confluent Platform because corsHandler.setVaryHeader is never invoked by conflux's AWS SDK Netty client, which only ever performs outbound HTTP/1.1 and HTTP/2 requests to AWS S3/DynamoDB; the vulnerable server-side code path is not present in its actual usage. This issue will be addressed in an upcoming release when an updated package is available from the vendor."
      }
    },
    {
      "id": "CVE-2026-85717",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        200,
        522
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured with a client-wide Realm and redirect following can disclose credentials after a cross-origin redirect because the Interceptors authentication path falls back to the client configuration after redirect handling clears the per-exchange realm. If the attacker-controlled target returns 401, the client can send Basic or Digest credentials or a Negotiate or NTLM token to that origin. Per-request realms are stripped correctly, and this issue is a residual bypass of the earlier cross-origin credential-stripping fixes. This issue is fixed in versions 2.16.1 and 3.0.12.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.12, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-85717"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-85717"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/43db7bba81430cbd61ec2dc2c7be464e0ff6a0ff"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/b66757bec34def2e9867bb2b77bd848b1112abb4"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/pull/2224"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-f8m2-889x-vw4x"
        },
        {
          "url": "https://github.com/advisories/GHSA-f8m2-889x-vw4x"
        }
      ],
      "published": "2026-09-17T16:18:15+00:00",
      "updated": "2026-09-30T17:31:44+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-85720",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        319,
        522
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can expose preemptive origin credentials because NettyRequestFactory and NettyRequestSender.sendRequestWithNewChannel attach Authorization to the plaintext CONNECT request before the TLS tunnel exists. Basic or Digest credentials and per-connection NTLM, Kerberos, or SPNEGO tokens intended for the origin are therefore visible to the proxy and to observers on the client-to-proxy hop. The tunneled request still receives origin Authorization after the tunnel is established, while Proxy-Authorization remains on CONNECT for its intended proxy recipient. This issue is fixed in versions 2.16.1 and 3.0.12.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.12, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-85720"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-85720"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/9dba5ac988b7e750551f59b2eab550b60ac8a0d6"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/d07dbc79f5cf378f63c246f6101d7579ace55acc"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/pull/2234"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-xr57-gcx8-52hf"
        },
        {
          "url": "https://github.com/advisories/GHSA-xr57-gcx8-52hf"
        }
      ],
      "published": "2026-09-17T17:16:51+00:00",
      "updated": "2026-09-24T21:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-85721",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        409
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 path uses ChannelManager.newHttpContentDecompressor() to install Http1ContentDecompressor without a cumulative output-size limit. A hostile or compromised server, or an attacker who can alter a response in transit, can send a small gzip, deflate, or snappy response that expands across chunks until the client exhausts its heap and raises OutOfMemoryError; brotli and zstd are also affected when their optional codecs are present. In versions 3.0.8 through 3.0.10, the HTTP/2 decompressor is also unbounded, so switching protocols does not mitigate the issue on those releases. A limit applied to each decode call is insufficient because the response can be delivered as many small chunks, so the fixed implementation tracks total decompressed bytes for the whole response. This issue is fixed in versions 2.16.1 and 3.0.12.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.12, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-85721"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-85721"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-85721"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/5ee2841cbf268bba4a200578be3938ccfc6cc6d6"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/663a1a91757904b22cfe37e2e6049f1f8ea6ae59"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/e1871a19972fb496be1b8ac6be11d79e22ff2162"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/e9f2f7423e0f6503f529656f2955a1317e56ba14"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-7grg-jcf7-rpmx"
        },
        {
          "url": "https://github.com/advisories/GHSA-7grg-jcf7-rpmx"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85721"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-85721"
        }
      ],
      "published": "2026-09-17T16:18:16+00:00",
      "updated": "2026-09-30T17:43:24+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@2.15.0",
          "versions": [
            {
              "version": "2.15.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:7e4e8092-ea72-4a1e-b5b3-01933a5d8f05/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0f90b11d-77c4-4807-b25d-ffd7c4156606/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.asynchttpclient/async-http-client@2.15.0"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-13505",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        772
      ],
      "description": "In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material held by the AES and DESede engines, the SP 800-90A DRBGs, SymmetricSecretKey and the PBKD and scrypt parameter classes was zeroised on garbage collection by overriding Object.finalize. Finalization runs at an unspecified time and in an unspecified order and is serviced by a single finalizer thread, so where objects carrying a finalizer are allocated faster than that thread retires them the pending-finalization queue grows without bound: disposal falls arbitrarily far behind, which can contribute to an OutOfMemoryError under load, and the key material those objects hold stays resident in the heap for as long as they are queued, defeating the purpose of the zeroisation. The behaviour was not a problem on Java 8 or Java 11; it is later JVMs, on which finalization has been deprecated and progressively de-emphasised, where it becomes one. Disposal of these classes now runs from a java.lang.ref.Cleaner registered in the multi-release jdk1.9 overlay, so on Java 9 and later it no longer depends on the finalizer being scheduled. Bouncy Castle for Java (bcprov) and Bouncy Castle for Java LTS are not affected, as neither implements the finalizer-based zeroisation scheme.",
      "recommendation": "Upgrade org.bouncycastle:bc-fips to version 1.0.2.7, 2.0.2, 2.1.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13505"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13505"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-13505"
        },
        {
          "url": "https://github.com/advisories/GHSA-98j2-6v39-78w8"
        },
        {
          "url": "https://github.com/bcgit/bc-java"
        },
        {
          "url": "https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9013505"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13505"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13505"
        }
      ],
      "published": "2026-08-08T02:17:16+00:00",
      "updated": "2026-09-03T16:44:20+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bc-fips@2.1.2",
          "versions": [
            {
              "version": "2.1.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:169aad26-1f9c-4ac9-808a-8fc98a9d2c26/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:26d3ab9a-48d7-467f-b70e-74852e525d1e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-13506",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        674
      ],
      "description": "In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).",
      "recommendation": "Upgrade org.bouncycastle:bc-fips to version 1.0.2.7, 2.0.2, 2.1.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13506"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13506"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-13506"
        },
        {
          "url": "https://github.com/advisories/GHSA-qp49-qgx5-5m26"
        },
        {
          "url": "https://github.com/bcgit/bc-java"
        },
        {
          "url": "https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84"
        },
        {
          "url": "https://github.com/bcgit/bc-java/wiki/CVE-2026-13506"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13506"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13506"
        }
      ],
      "published": "2026-08-03T04:16:39+00:00",
      "updated": "2026-08-28T16:41:22+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bc-fips@2.1.2",
          "versions": [
            {
              "version": "2.1.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:169aad26-1f9c-4ac9-808a-8fc98a9d2c26/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:26d3ab9a-48d7-467f-b70e-74852e525d1e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-8763",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        295
      ],
      "description": "In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).",
      "recommendation": "Upgrade org.bouncycastle:bc-fips to version 1.0.2.7, 2.0.2, 2.1.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8763"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8763"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-8763"
        },
        {
          "url": "https://github.com/advisories/GHSA-9pwp-9qqc-pr26"
        },
        {
          "url": "https://github.com/bcgit/bc-java"
        },
        {
          "url": "https://github.com/bcgit/bc-java/commit/2c28b253a44681fbbc562561eab6ad383d2ae558"
        },
        {
          "url": "https://github.com/bcgit/bc-java/releases/tag/r1rv85v2"
        },
        {
          "url": "https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763"
        },
        {
          "url": "https://github.com/bcgit/bc-java/wiki/CVE-2026-8763"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8763"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8763"
        }
      ],
      "published": "2026-08-03T01:16:45+00:00",
      "updated": "2026-09-02T14:28:48+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bc-fips@2.1.2",
          "versions": [
            {
              "version": "2.1.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:169aad26-1f9c-4ac9-808a-8fc98a9d2c26/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:26d3ab9a-48d7-467f-b70e-74852e525d1e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-8798",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [],
      "cwes": [
        835
      ],
      "description": "In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound. RDSEED and RDRAND report failure through their carry flag, and the JNI seeding routine spun re-issuing the instruction for as long as that flag stayed clear, so a persistent failure of the on-chip entropy source - whether from a hardware fault, from the underlying DRBG being exhausted by contention across many cores, or from a hypervisor that does not provide the instruction - left the calling thread looping indefinitely inside the JNI call, where it could be neither interrupted nor timed out. Any operation drawing from the native entropy source could therefore hang, denying service to the application. The retry loops are now bounded (200 attempts for RDSEED and 20 for RDRAND, twice the baselines given in Intel's Digital Random Number Generator software implementation guide), pausing between attempts and, on exhaustion, clearing any partially written buffer and throwing rather than continuing to spin. The clear is performed by an un-elidable memzero, which uses a volatile pointer and an assembly memory barrier so that a compiler cannot optimise the erase away as a dead store. Bouncy Castle for Java (bcprov) is not affected, as it has no native entropy source; the 1.0.X and 2.0.X FIPS series are not affected.",
      "recommendation": "Upgrade org.bouncycastle:bc-fips to version 2.1.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8798"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-8798"
        },
        {
          "url": "https://github.com/advisories/GHSA-v6w3-qrh8-qccc"
        },
        {
          "url": "https://github.com/bcgit/bc-java"
        },
        {
          "url": "https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908798"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8798"
        }
      ],
      "published": "2026-08-08T01:16:31+00:00",
      "updated": "2026-09-03T16:44:20+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bc-fips@2.1.2",
          "versions": [
            {
              "version": "2.1.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:4256e262-c833-4987-be63-a30fa2d43e1e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:9f255799-c6e4-4e53-8273-34a0b0c9075e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:169aad26-1f9c-4ac9-808a-8fc98a9d2c26/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:efa4c907-a3d7-4b86-8481-68495acd4714/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:26d3ab9a-48d7-467f-b70e-74852e525d1e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:50e819ac-66f5-4cad-af72-99db2bcc37d7/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-45292",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggage propagation implementation in opentelemetry-api and opentelemetry-extension-trace-propagators. Parsing oversized baggage causes unbounded memory allocation and CPU consumption. Because baggage is automatically re-injected into every outgoing request, the effect can fan out to downstream services that never received the original malicious request. This vulnerability is fixed in 1.62.0.",
      "recommendation": "Upgrade io.opentelemetry:opentelemetry-api to version 1.62.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45292"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28573"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-45292"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-45292"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482785"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/commit/03837d3c1763bc35464aea1078671e2ef2336a5f"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/pull/8380"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/releases/tag/v1.62.0"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/security/advisories/GHSA-rcgg-9c38-7xpx"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45292"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45292.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45292"
        }
      ],
      "published": "2026-05-28T17:16:32+00:00",
      "updated": "2026-09-10T13:20:17+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.opentelemetry/opentelemetry-api@1.39.0",
          "versions": [
            {
              "version": "1.39.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c43b002-af9d-4b9d-bfed-e93f1b0505c2/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.39.0"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.39.0"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.39.0"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.39.0"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.39.0"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.39.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.39.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the OpenTelemetry W3C Baggage propagator is not wired to parse inbound request headers, so the unbounded baggage-allocation path is not reachable."
      }
    },
    {
      "id": "CVE-2026-40984",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.\n\nAffected versions:\nmicrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18; 1.9.0 through 1.9.17.\nmicrometer-jetty11 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.\nmicrometer-jetty12 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.",
      "recommendation": "Upgrade io.micrometer:micrometer-core to version 1.16.6, 1.15.12",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40984"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36839"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37390"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50848"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50849"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62260"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66488"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66545"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40984"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-40984"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486716"
        },
        {
          "url": "https://github.com/micrometer-metrics/micrometer"
        },
        {
          "url": "https://github.com/micrometer-metrics/micrometer/commit/36da131525228188a36779a28471a76c79213dd4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40984"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40984.json"
        },
        {
          "url": "https://spring.io/security/cve-2026-40984"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40984"
        }
      ],
      "published": "2026-06-09T05:16:34+00:00",
      "updated": "2026-09-14T13:18:33+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.micrometer/micrometer-core@1.14.4",
          "versions": [
            {
              "version": "1.14.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:67fbf0d0-2f94-467a-ad73-c35e11c8ad34/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2005-2541",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 10,
          "severity": "high",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "description": "Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2005-2541"
        },
        {
          "url": "http://marc.info/?l=bugtraq&m=112327628230258&w=2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2005-2541"
        },
        {
          "url": "https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c@%3Cissues.guacamole.apache.org%3E"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2005-2541"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2005-2541"
        }
      ],
      "published": "2005-08-10T04:00:00+00:00",
      "updated": "2026-04-16T00:27:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2018-1000654",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:C"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a crafted file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-1000654"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00009.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00018.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/105151"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-1000654"
        },
        {
          "url": "https://gitlab.com/gnutls/libtasn1/issues/4"
        },
        {
          "url": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000654"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5352-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-1000654"
        }
      ],
      "published": "2018-08-20T19:31:44+00:00",
      "updated": "2026-06-17T01:33:01+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.13-6.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2018-1000879",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: NULL Pointer Dereference vulnerability in ACL parser - libarchive/archive_acl.c, archive_acl_from_text_l() that can result in Crash/DoS. This attack appear to be exploitable via the victim must open a specially crafted archive file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-1000879"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00055.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/106324"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-1000879"
        },
        {
          "url": "https://bugs.launchpad.net/ubuntu/+source/libarchive/+bug/1794909"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/1105"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/1105/commits/15bf44fd2c1ad0e3fd87048b3fcc90c4dcff1175"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBOCC2M6YGPZA6US43YK4INPSJZZHRTG/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W645KCLWFDBDGFJHG57WOVXGE62QSIJI/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVXA7PHINVT6DFF6PRLTDTVTXKDLVHNF/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000879"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-1000879"
        }
      ],
      "published": "2018-12-20T17:29:01+00:00",
      "updated": "2026-10-08T21:17:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2018-1000880",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        119
      ],
      "description": "libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards) contains a CWE-20: Improper Input Validation vulnerability in WARC parser - libarchive/archive_read_support_format_warc.c, _warc_read() that can result in DoS - quasi-infinite run time and disk usage from tiny file. This attack appear to be exploitable via the victim must open a specially crafted WARC file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-1000880"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00055.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/106324"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-1000880"
        },
        {
          "url": "https://bugs.launchpad.net/ubuntu/+source/libarchive/+bug/1794909"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/1105"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/1105/commits/9c84b7426660c09c18cc349f6d70b5f8168b5680"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBOCC2M6YGPZA6US43YK4INPSJZZHRTG/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W645KCLWFDBDGFJHG57WOVXGE62QSIJI/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVXA7PHINVT6DFF6PRLTDTVTXKDLVHNF/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000880"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-3859-1"
        },
        {
          "url": "https://usn.ubuntu.com/3859-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-1000880"
        },
        {
          "url": "https://www.debian.org/security/2018/dsa-4360"
        }
      ],
      "published": "2018-12-20T17:29:01+00:00",
      "updated": "2026-10-08T21:17:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2018-1121",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:P/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        367,
        362
      ],
      "description": "procps-ng, procps is vulnerable to a process hiding through race condition. Since the kernel's proc_pid_readdir() returns PID entries in ascending numeric order, a process occupying a high PID can use inotify events to determine when the process list is being scanned, and fork/exec to obtain a lower PID, thus avoiding enumeration. An unprivileged attacker can hide a process from procps-ng's utilities by exploiting a race condition in reading /proc/PID entries. This vulnerability affects procps and procps-ng up to version 3.3.15, newer versions might be affected also.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-1121"
        },
        {
          "url": "http://seclists.org/oss-sec/2018/q2/122"
        },
        {
          "url": "http://www.securityfocus.com/bid/104214"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-1121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1121"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1121"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-1121"
        },
        {
          "url": "https://www.exploit-db.com/exploits/44806/"
        },
        {
          "url": "https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt"
        }
      ],
      "published": "2018-06-13T20:29:00+00:00",
      "updated": "2026-06-17T01:50:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.15-14.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2018-19211",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a \"dubious character `*' in name or alias field\" detection.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-19211"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-19211"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1643754"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-19211"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5477-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-19211"
        }
      ],
      "published": "2018-11-12T19:29:00+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2018-20225",
      "ratings": [
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        20
      ],
      "description": "An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-20225"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-20225"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1835736"
        },
        {
          "url": "https://cowlicks.website/posts/arbitrary-code-execution-from-pips-extra-index-url.html"
        },
        {
          "url": "https://lists.apache.org/thread.html/rb1adce798445facd032870d644eb39c4baaf9c4a7dd5477d12bb6ab2@%3Cgithub.arrow.apache.org%3E"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-20225"
        },
        {
          "url": "https://pip.pypa.io/en/stable/news/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-20225"
        }
      ],
      "published": "2020-05-08T18:15:10+00:00",
      "updated": "2026-06-17T01:52:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable. "
      }
    },
    {
      "id": "CVE-2018-20657",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        772
      ],
      "description": "The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-20657"
        },
        {
          "url": "http://www.securityfocus.com/bid/106444"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2019:3352"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-20657"
        },
        {
          "url": "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88539"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2018-20657.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2019-3352.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-20657"
        },
        {
          "url": "https://support.f5.com/csp/article/K62602089"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-20657"
        }
      ],
      "published": "2019-01-02T14:29:00+00:00",
      "updated": "2026-06-17T01:53:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2018-20839",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:P/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "description": "systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the KDGKBMODE (aka current keyboard mode) check is mishandled.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-20839"
        },
        {
          "url": "http://www.securityfocus.com/bid/108389"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-20839"
        },
        {
          "url": "https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1803993"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/9725f1a10f80f5e0ae7d9b60547458622aeb322f"
        },
        {
          "url": "https://github.com/systemd/systemd/pull/12378"
        },
        {
          "url": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-20839"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20190530-0002/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-20839"
        }
      ],
      "published": "2019-05-17T04:29:00+00:00",
      "updated": "2026-06-17T01:53:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.19",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.19",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.19",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2018-25282",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        674
      ],
      "description": "Nmap 7.70 contains a denial of service vulnerability that allows local attackers to crash the application by processing malicious XML files with exponential entity expansion. Attackers can create a crafted XML file with nested entity definitions and open it through ZenMap's scan import functionality to cause the program to consume excessive system resources and crash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-25282"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-25282"
        },
        {
          "url": "https://nmap.org/dist/nmap-7.70-setup.exe"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-25282"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-25282"
        },
        {
          "url": "https://www.exploit-db.com/exploits/45357"
        },
        {
          "url": "https://www.vulncheck.com/advisories/nmap-denial-of-service-via-xml-entity-expansion"
        }
      ],
      "published": "2026-04-26T22:17:28+00:00",
      "updated": "2026-06-17T01:55:09+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:7.92-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2019-12904",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:P/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        668
      ],
      "description": "In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.) NOTE: the vendor's position is that the issue report cannot be validated because there is no description of an attack",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-12904"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00049.html"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-12904"
        },
        {
          "url": "https://dev.gnupg.org/T4541"
        },
        {
          "url": "https://github.com/gpg/libgcrypt/commit/a4c561aab1014c3630bc88faf6f5246fee16b020"
        },
        {
          "url": "https://github.com/gpg/libgcrypt/commit/daedbbb5541cd8ecda1459d3b843ea4d92788762"
        },
        {
          "url": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gcrypt-devel/2019-July/004760.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-12904"
        },
        {
          "url": "https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-12904.html"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-12904"
        }
      ],
      "published": "2019-06-20T00:15:10+00:00",
      "updated": "2026-06-17T02:15:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.8.5-8.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2019-14250",
      "ratings": [
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190,
        787
      ],
      "description": "An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-14250"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00056.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00057.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00058.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00078.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00004.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/109354"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-14250"
        },
        {
          "url": "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=90924"
        },
        {
          "url": "https://gcc.gnu.org/ml/gcc-patches/2019-07/msg01003.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-14250"
        },
        {
          "url": "https://security.gentoo.org/glsa/202007-39"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20190822-0002/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4326-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4336-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4336-2"
        },
        {
          "url": "https://usn.ubuntu.com/4326-1/"
        },
        {
          "url": "https://usn.ubuntu.com/4336-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-14250"
        }
      ],
      "published": "2019-07-24T04:15:12+00:00",
      "updated": "2026-10-08T21:17:12+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2019-16866",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        755,
        908
      ],
      "description": "Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-16866"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-16866"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/blob/release-1.9.4/doc/Changelog"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E65NCWZZB2D75ZIYWPXKMVGSGNYW4JMC/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MLRHE7TQFAOV4MB2ELTOGESZYUL65NUJ/"
        },
        {
          "url": "https://nlnetlabs.nl/downloads/unbound/CVE-2019-16866.txt"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-16866"
        },
        {
          "url": "https://seclists.org/bugtraq/2019/Oct/23"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4149-1"
        },
        {
          "url": "https://usn.ubuntu.com/4149-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-16866"
        },
        {
          "url": "https://www.debian.org/security/2019/dsa-4544"
        }
      ],
      "published": "2019-10-03T19:15:09+00:00",
      "updated": "2026-10-08T21:17:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2019-19244",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-19244"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-19244"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf"
        },
        {
          "url": "https://github.com/sqlite/sqlite/commit/e59c562b3f6894f84c715772c4b116d7b5c01348"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-19244"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4205-1"
        },
        {
          "url": "https://usn.ubuntu.com/4205-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-19244"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2020.html"
        }
      ],
      "published": "2019-11-25T20:15:11+00:00",
      "updated": "2026-10-08T21:17:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.26.0-21.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2019-7317",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 2.6,
          "severity": "info",
          "method": "CVSSv2",
          "vector": "AV:N/AC:H/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-7317"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00002.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00029.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00084.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00038.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00044.html"
        },
        {
          "url": "http://packetstormsecurity.com/files/152561/Slackware-Security-Advisory-libpng-Updates.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/108098"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2019:1265"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2019:1267"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2019:1269"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2019:1308"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2019:1309"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2019:1310"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2019:2494"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2019:2495"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2019:2585"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2019:2590"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2019:2592"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2019:2737"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-7317"
        },
        {
          "url": "https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=12803"
        },
        {
          "url": "https://github.com/glennrp/libpng/issues/275"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2019-7317.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2019-1310.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2019/05/msg00032.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2019/05/msg00038.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-7317"
        },
        {
          "url": "https://seclists.org/bugtraq/2019/Apr/30"
        },
        {
          "url": "https://seclists.org/bugtraq/2019/Apr/36"
        },
        {
          "url": "https://seclists.org/bugtraq/2019/May/56"
        },
        {
          "url": "https://seclists.org/bugtraq/2019/May/59"
        },
        {
          "url": "https://seclists.org/bugtraq/2019/May/67"
        },
        {
          "url": "https://security.gentoo.org/glsa/201908-02"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20190719-0005/"
        },
        {
          "url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03977en_us"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-3962-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-3991-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-3997-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4080-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4083-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8639-1"
        },
        {
          "url": "https://usn.ubuntu.com/3962-1/"
        },
        {
          "url": "https://usn.ubuntu.com/3991-1/"
        },
        {
          "url": "https://usn.ubuntu.com/3997-1/"
        },
        {
          "url": "https://usn.ubuntu.com/4080-1/"
        },
        {
          "url": "https://usn.ubuntu.com/4083-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-7317"
        },
        {
          "url": "https://www.debian.org/security/2019/dsa-4435"
        },
        {
          "url": "https://www.debian.org/security/2019/dsa-4448"
        },
        {
          "url": "https://www.debian.org/security/2019/dsa-4451"
        },
        {
          "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2019-13/#CVE-2019-7317"
        },
        {
          "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2019-15/#CVE-2019-7317"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuApr2021.html"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuoct2021.html"
        },
        {
          "url": "https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"
        }
      ],
      "published": "2019-02-04T08:29:00+00:00",
      "updated": "2026-06-17T02:40:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.6.34-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2019-8905",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.6,
          "severity": "info",
          "method": "CVSSv2",
          "vector": "AV:L/AC:L/Au:N/C:P/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-8905"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00027.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00053.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/107137"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-8905"
        },
        {
          "url": "https://bugs.astron.com/view.php?id=63"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2019/02/msg00044.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-8905"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-3911-1"
        },
        {
          "url": "https://usn.ubuntu.com/3911-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-8905"
        }
      ],
      "published": "2019-02-18T17:29:00+00:00",
      "updated": "2026-06-17T02:42:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "5.33-27.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable.\nFor python:"
      }
    },
    {
      "id": "CVE-2019-8906",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.6,
          "severity": "info",
          "method": "CVSSv2",
          "vector": "AV:L/AC:L/Au:N/C:P/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-8906"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00027.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00053.html"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-8906"
        },
        {
          "url": "https://bugs.astron.com/view.php?id=64"
        },
        {
          "url": "https://github.com/file/file/commit/2858eaf99f6cc5aae129bcbf1e24ad160240185f"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-8906"
        },
        {
          "url": "https://support.apple.com/kb/HT209599"
        },
        {
          "url": "https://support.apple.com/kb/HT209600"
        },
        {
          "url": "https://support.apple.com/kb/HT209601"
        },
        {
          "url": "https://support.apple.com/kb/HT209602"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-3911-1"
        },
        {
          "url": "https://usn.ubuntu.com/3911-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-8906"
        }
      ],
      "published": "2019-02-18T17:29:01+00:00",
      "updated": "2026-10-08T21:17:20+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "5.33-27.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable.\nFor python:"
      }
    },
    {
      "id": "CVE-2019-9674",
      "ratings": [
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-9674"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00041.html"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-9674"
        },
        {
          "url": "https://bugs.python.org/issue36260"
        },
        {
          "url": "https://bugs.python.org/issue36462"
        },
        {
          "url": "https://github.com/python/cpython/blob/master/Lib/zipfile.py"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-9674"
        },
        {
          "url": "https://python-security.readthedocs.io/security.html#archives-and-zip-bomb"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20200221-0003/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4428-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4754-3"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6891-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7212-1"
        },
        {
          "url": "https://usn.ubuntu.com/4428-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-9674"
        },
        {
          "url": "https://www.python.org/news/security/"
        }
      ],
      "published": "2020-02-04T15:15:11+00:00",
      "updated": "2026-10-08T21:17:20+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2019-9923",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-9923"
        },
        {
          "url": "http://git.savannah.gnu.org/cgit/tar.git/commit/?id=cb07844454d8cc9fb21f53ace75975f91185a120"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00077.html"
        },
        {
          "url": "http://savannah.gnu.org/bugs/?55369"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-9923"
        },
        {
          "url": "https://bugs.launchpad.net/ubuntu/+source/tar/+bug/1810241"
        },
        {
          "url": "https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E"
        },
        {
          "url": "https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-9923"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4692-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-9923"
        }
      ],
      "published": "2019-03-22T08:29:00+00:00",
      "updated": "2026-06-17T02:44:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2019-9936",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is related to ext/fts5/fts5_hash.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-9936"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00026.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/107562"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-9936"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EXD2GYJVTDGEQPUNMMMC5TB7MQXOBBMO/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N66U5PY5UJU4XBFZJH7QNKIDNAVIB4OP/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-9936"
        },
        {
          "url": "https://security.gentoo.org/glsa/201908-09"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20190416-0005/"
        },
        {
          "url": "https://sqlite.org/src/info/b3fa58dd7403dbd4"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4019-1"
        },
        {
          "url": "https://usn.ubuntu.com/4019-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-9936"
        },
        {
          "url": "https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg114382.html"
        },
        {
          "url": "https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg114394.html"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpujan2020.html"
        },
        {
          "url": "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"
        }
      ],
      "published": "2019-03-22T08:29:00+00:00",
      "updated": "2026-06-17T02:44:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.26.0-21.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2019-9937",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference in fts5ChunkIterate in sqlite3.c. This is related to ext/fts5/fts5_hash.c and ext/fts5/fts5_index.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-9937"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00026.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/107562"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-9937"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EXD2GYJVTDGEQPUNMMMC5TB7MQXOBBMO/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N66U5PY5UJU4XBFZJH7QNKIDNAVIB4OP/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-9937"
        },
        {
          "url": "https://security.gentoo.org/glsa/201908-09"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20190416-0005/"
        },
        {
          "url": "https://sqlite.org/src/info/45c73deb440496e8"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4019-1"
        },
        {
          "url": "https://usn.ubuntu.com/4019-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-9937"
        },
        {
          "url": "https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg114383.html"
        },
        {
          "url": "https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg114393.html"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpujan2020.html"
        },
        {
          "url": "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"
        }
      ],
      "published": "2019-03-22T08:29:00+00:00",
      "updated": "2026-06-17T02:44:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.26.0-21.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2020-19185",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-19185"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-19185"
        },
        {
          "url": "https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc1.md"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19185"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231006-0005/"
        },
        {
          "url": "https://support.apple.com/kb/HT214036"
        },
        {
          "url": "https://support.apple.com/kb/HT214037"
        },
        {
          "url": "https://support.apple.com/kb/HT214038"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-19185"
        }
      ],
      "published": "2023-08-22T19:15:57+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2020-19186",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-19186"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-19186"
        },
        {
          "url": "https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc2.md"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19186"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231006-0005/"
        },
        {
          "url": "https://support.apple.com/kb/HT214036"
        },
        {
          "url": "https://support.apple.com/kb/HT214037"
        },
        {
          "url": "https://support.apple.com/kb/HT214038"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-19186"
        }
      ],
      "published": "2023-08-22T19:15:58+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2020-19187",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-19187"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-19187"
        },
        {
          "url": "https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc3.md"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19187"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231006-0005/"
        },
        {
          "url": "https://support.apple.com/kb/HT214036"
        },
        {
          "url": "https://support.apple.com/kb/HT214037"
        },
        {
          "url": "https://support.apple.com/kb/HT214038"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-19187"
        }
      ],
      "published": "2023-08-22T19:15:59+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2020-19188",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-19188"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-19188"
        },
        {
          "url": "https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc4.md"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19188"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231006-0005/"
        },
        {
          "url": "https://support.apple.com/kb/HT214036"
        },
        {
          "url": "https://support.apple.com/kb/HT214037"
        },
        {
          "url": "https://support.apple.com/kb/HT214038"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-19188"
        }
      ],
      "published": "2023-08-22T19:16:00+00:00",
      "updated": "2026-10-08T21:17:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2020-19189",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-19189"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-19189"
        },
        {
          "url": "https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc5.md"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00033.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19189"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231006-0005/"
        },
        {
          "url": "https://support.apple.com/kb/HT214036"
        },
        {
          "url": "https://support.apple.com/kb/HT214037"
        },
        {
          "url": "https://support.apple.com/kb/HT214038"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6451-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-19189"
        }
      ],
      "published": "2023-08-22T19:16:01+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2020-19190",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-19190"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-19190"
        },
        {
          "url": "https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc6.md"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19190"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231006-0005/"
        },
        {
          "url": "https://support.apple.com/kb/HT214036"
        },
        {
          "url": "https://support.apple.com/kb/HT214037"
        },
        {
          "url": "https://support.apple.com/kb/HT214038"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-19190"
        }
      ],
      "published": "2023-08-22T19:16:01+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2020-35512",
      "ratings": [
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.2,
          "severity": "high",
          "method": "CVSSv2",
          "vector": "AV:L/AC:L/Au:N/C:C/I:C/A:C"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharing the same UID. When a set of policy rules references these usernames, D-Bus may free some memory in the heap, which is still used by data structures necessary for the other usernames sharing the UID, possibly leading to a crash or other undefined behaviors",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-35512"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35512"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-35512"
        },
        {
          "url": "https://bugs.gentoo.org/755392"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1909101"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket/security/advisories/GHSA-m7gr-wq6g-x327"
        },
        {
          "url": "https://gitlab.freedesktop.org/dbus/dbus/-/commit/2b7948ef907669e844b52c4fa2268d6e3162a70c%20%28dbus-1.13.18%29"
        },
        {
          "url": "https://gitlab.freedesktop.org/dbus/dbus/-/commit/dc94fe3d31adf72259adc31f343537151a6c0bdd%20%28dbus-1.10.32%29"
        },
        {
          "url": "https://gitlab.freedesktop.org/dbus/dbus/-/commit/f3b2574f0c9faa32a59efec905921f7ef4438a60%20%28dbus-1.12.20%29"
        },
        {
          "url": "https://gitlab.freedesktop.org/dbus/dbus/-/issues/305"
        },
        {
          "url": "https://gitlab.freedesktop.org/dbus/dbus/-/issues/305#note_829128"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35512"
        },
        {
          "url": "https://security-tracker.debian.org/tracker/CVE-2020-35512"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5244-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5244-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-35512"
        }
      ],
      "published": "2021-02-15T17:15:12+00:00",
      "updated": "2026-06-17T03:13:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.12.8-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.12.8-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.12.8-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.12.8-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.12.8-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2021-20193",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        401,
        125
      ],
      "description": "A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-20193"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-20193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1917565"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/tar.git/commit/?id=d9d4435692150fa8ff68e1b1a473d187cc3fd777"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20193"
        },
        {
          "url": "https://savannah.gnu.org/bugs/?59897"
        },
        {
          "url": "https://security.gentoo.org/glsa/202105-29"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5329-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-20193"
        }
      ],
      "published": "2021-03-26T17:15:12+00:00",
      "updated": "2026-10-08T21:17:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2021-24032",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 1.9,
          "severity": "info",
          "method": "CVSSv2",
          "vector": "AV:L/AC:M/Au:N/C:P/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        277,
        276
      ],
      "description": "Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-24032"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-24032"
        },
        {
          "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=982519"
        },
        {
          "url": "https://github.com/advisories/GHSA-ffqj-7pgc-cmj5"
        },
        {
          "url": "https://github.com/facebook/zstd/issues/2491"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-24032"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4760-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5720-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-24032"
        },
        {
          "url": "https://www.facebook.com/security/advisories/cve-2021-24032"
        }
      ],
      "published": "2021-03-04T21:15:12+00:00",
      "updated": "2026-10-08T21:17:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.4.4-1.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2021-31879",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.8,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:P/I:P/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        601
      ],
      "description": "GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-31879"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-31879"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31879"
        },
        {
          "url": "https://savannah.gnu.org/bugs/?56909"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20210618-0002/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-31879"
        }
      ],
      "published": "2021-04-29T05:15:08+00:00",
      "updated": "2026-10-08T21:17:35+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.19.5-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2021-39537",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-39537"
        },
        {
          "url": "http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/patch-ncurses_tinfo_captoinfo.c?rev=1.1&content-type=text/x-cvsweb-markup"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2022/Oct/28"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2022/Oct/41"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2022/Oct/43"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2022/Oct/45"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-39537"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2021-10/msg00023.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-39537"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230427-0012/"
        },
        {
          "url": "https://support.apple.com/kb/HT213443"
        },
        {
          "url": "https://support.apple.com/kb/HT213444"
        },
        {
          "url": "https://support.apple.com/kb/HT213488"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5477-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-39537"
        }
      ],
      "published": "2021-09-20T16:15:12+00:00",
      "updated": "2026-10-08T21:17:39+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2021-3997",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-3997"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-3997"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2024639"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/5b1cf7a9be37e20133c0208005274ce4a5b5c6a1"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-3997"
        },
        {
          "url": "https://security.gentoo.org/glsa/202305-15"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5226-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-3997"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2022/01/10/2"
        }
      ],
      "published": "2022-08-23T20:15:08+00:00",
      "updated": "2026-06-17T04:06:21+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.19",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.19",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.19",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2021-4209",
      "ratings": [
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-4209"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-4209"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2044156"
        },
        {
          "url": "https://gitlab.com/gnutls/gnutls/-/commit/3db352734472d851318944db13be73da61300568"
        },
        {
          "url": "https://gitlab.com/gnutls/gnutls/-/issues/1306"
        },
        {
          "url": "https://gitlab.com/gnutls/gnutls/-/merge_requests/1503"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-4209"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20220915-0005/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5550-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5750-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-4209"
        }
      ],
      "published": "2022-08-24T16:15:09+00:00",
      "updated": "2026-06-17T04:19:13+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.16-8.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2022-27943",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        674
      ],
      "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-27943"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-27943"
        },
        {
          "url": "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=1a770b01ef415e114164b6151d1e55acdee09371"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=9234cdca6ee88badfc00297e72f13dac4e540c79"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=fc968115a742d9e4674d9725ce9c2106b91b6ead"
        },
        {
          "url": "https://gcc.gnu.org/pipermail/gcc-patches/2022-March/592244.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27943"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=28995"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-27943"
        }
      ],
      "published": "2022-03-26T13:15:07+00:00",
      "updated": "2026-10-08T19:16:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-3219",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-3219"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-3219"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2127010"
        },
        {
          "url": "https://dev.gnupg.org/D556"
        },
        {
          "url": "https://dev.gnupg.org/T5993"
        },
        {
          "url": "https://marc.info/?l=oss-security&m=165696590211434&w=4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3219"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230324-0001/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-3219"
        }
      ],
      "published": "2023-02-23T20:15:12+00:00",
      "updated": "2026-06-17T04:59:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.2.20-4.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-41409",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-41409"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-41409"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/issues/141"
        },
        {
          "url": "https://github.com/advisories/GHSA-4qfx-v7wh-3q4j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41409"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41409"
        }
      ],
      "published": "2023-07-18T14:15:12+00:00",
      "updated": "2026-06-17T05:03:09+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "10.32-3.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-4899",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        400
      ],
      "description": "A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-4899"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:0894"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:1141"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-4899"
        },
        {
          "url": "https://bugzilla.redhat.com/2179864"
        },
        {
          "url": "https://bugzilla.redhat.com/2188109"
        },
        {
          "url": "https://bugzilla.redhat.com/2188113"
        },
        {
          "url": "https://bugzilla.redhat.com/2188115"
        },
        {
          "url": "https://bugzilla.redhat.com/2188116"
        },
        {
          "url": "https://bugzilla.redhat.com/2188117"
        },
        {
          "url": "https://bugzilla.redhat.com/2188118"
        },
        {
          "url": "https://bugzilla.redhat.com/2188119"
        },
        {
          "url": "https://bugzilla.redhat.com/2188120"
        },
        {
          "url": "https://bugzilla.redhat.com/2188121"
        },
        {
          "url": "https://bugzilla.redhat.com/2188122"
        },
        {
          "url": "https://bugzilla.redhat.com/2188123"
        },
        {
          "url": "https://bugzilla.redhat.com/2188124"
        },
        {
          "url": "https://bugzilla.redhat.com/2188125"
        },
        {
          "url": "https://bugzilla.redhat.com/2188127"
        },
        {
          "url": "https://bugzilla.redhat.com/2188128"
        },
        {
          "url": "https://bugzilla.redhat.com/2188129"
        },
        {
          "url": "https://bugzilla.redhat.com/2188130"
        },
        {
          "url": "https://bugzilla.redhat.com/2188131"
        },
        {
          "url": "https://bugzilla.redhat.com/2188132"
        },
        {
          "url": "https://bugzilla.redhat.com/2224211"
        },
        {
          "url": "https://bugzilla.redhat.com/2224212"
        },
        {
          "url": "https://bugzilla.redhat.com/2224213"
        },
        {
          "url": "https://bugzilla.redhat.com/2224214"
        },
        {
          "url": "https://bugzilla.redhat.com/2224215"
        },
        {
          "url": "https://bugzilla.redhat.com/2224216"
        },
        {
          "url": "https://bugzilla.redhat.com/2224217"
        },
        {
          "url": "https://bugzilla.redhat.com/2224218"
        },
        {
          "url": "https://bugzilla.redhat.com/2224219"
        },
        {
          "url": "https://bugzilla.redhat.com/2224220"
        },
        {
          "url": "https://bugzilla.redhat.com/2224221"
        },
        {
          "url": "https://bugzilla.redhat.com/2224222"
        },
        {
          "url": "https://bugzilla.redhat.com/2245014"
        },
        {
          "url": "https://bugzilla.redhat.com/2245015"
        },
        {
          "url": "https://bugzilla.redhat.com/2245016"
        },
        {
          "url": "https://bugzilla.redhat.com/2245017"
        },
        {
          "url": "https://bugzilla.redhat.com/2245018"
        },
        {
          "url": "https://bugzilla.redhat.com/2245019"
        },
        {
          "url": "https://bugzilla.redhat.com/2245020"
        },
        {
          "url": "https://bugzilla.redhat.com/2245021"
        },
        {
          "url": "https://bugzilla.redhat.com/2245022"
        },
        {
          "url": "https://bugzilla.redhat.com/2245023"
        },
        {
          "url": "https://bugzilla.redhat.com/2245024"
        },
        {
          "url": "https://bugzilla.redhat.com/2245026"
        },
        {
          "url": "https://bugzilla.redhat.com/2245027"
        },
        {
          "url": "https://bugzilla.redhat.com/2245028"
        },
        {
          "url": "https://bugzilla.redhat.com/2245029"
        },
        {
          "url": "https://bugzilla.redhat.com/2245030"
        },
        {
          "url": "https://bugzilla.redhat.com/2245031"
        },
        {
          "url": "https://bugzilla.redhat.com/2245032"
        },
        {
          "url": "https://bugzilla.redhat.com/2245033"
        },
        {
          "url": "https://bugzilla.redhat.com/2245034"
        },
        {
          "url": "https://bugzilla.redhat.com/2258771"
        },
        {
          "url": "https://bugzilla.redhat.com/2258772"
        },
        {
          "url": "https://bugzilla.redhat.com/2258773"
        },
        {
          "url": "https://bugzilla.redhat.com/2258774"
        },
        {
          "url": "https://bugzilla.redhat.com/2258775"
        },
        {
          "url": "https://bugzilla.redhat.com/2258776"
        },
        {
          "url": "https://bugzilla.redhat.com/2258777"
        },
        {
          "url": "https://bugzilla.redhat.com/2258778"
        },
        {
          "url": "https://bugzilla.redhat.com/2258779"
        },
        {
          "url": "https://bugzilla.redhat.com/2258780"
        },
        {
          "url": "https://bugzilla.redhat.com/2258781"
        },
        {
          "url": "https://bugzilla.redhat.com/2258782"
        },
        {
          "url": "https://bugzilla.redhat.com/2258783"
        },
        {
          "url": "https://bugzilla.redhat.com/2258784"
        },
        {
          "url": "https://bugzilla.redhat.com/2258785"
        },
        {
          "url": "https://bugzilla.redhat.com/2258787"
        },
        {
          "url": "https://bugzilla.redhat.com/2258788"
        },
        {
          "url": "https://bugzilla.redhat.com/2258789"
        },
        {
          "url": "https://bugzilla.redhat.com/2258790"
        },
        {
          "url": "https://bugzilla.redhat.com/2258791"
        },
        {
          "url": "https://bugzilla.redhat.com/2258792"
        },
        {
          "url": "https://bugzilla.redhat.com/2258793"
        },
        {
          "url": "https://bugzilla.redhat.com/2258794"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2179864"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188109"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188113"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188115"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188116"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188117"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188118"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188119"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188120"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188122"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188123"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188124"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188125"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188127"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188128"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188129"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188130"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188131"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188132"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224211"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224212"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224213"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224214"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224215"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224216"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224217"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224219"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224222"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245014"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245015"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245016"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245017"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245018"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245019"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245020"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245021"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245022"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245023"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245024"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245026"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245027"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245028"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245029"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245030"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245031"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245032"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245033"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258771"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258772"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258773"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258774"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258775"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258776"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258777"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258778"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258779"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258780"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258781"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258782"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258783"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258784"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258785"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258787"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258788"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258789"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258790"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258791"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258792"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258793"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258794"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4899"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21911"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21919"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21920"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21929"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21933"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21935"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21940"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21945"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21946"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21947"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21953"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21955"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21962"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21972"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21976"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21977"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21980"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21982"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22005"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22007"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22008"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22032"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22033"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22038"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22046"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22048"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22054"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22056"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22057"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22058"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22059"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22064"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22065"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22066"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22068"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22070"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22078"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22079"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22084"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22092"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22097"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22103"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22104"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22110"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22111"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22112"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22113"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22115"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20960"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20961"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20962"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20963"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20968"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20969"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20970"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20971"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20972"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20973"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20974"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20976"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20977"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20978"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20981"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20982"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20983"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20984"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20985"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20993"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21049"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21050"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21051"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21052"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21055"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21056"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21057"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21061"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21137"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21200"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-1141.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2024:0894"
        },
        {
          "url": "https://github.com/facebook/zstd"
        },
        {
          "url": "https://github.com/facebook/zstd/issues/3200"
        },
        {
          "url": "https://github.com/facebook/zstd/pull/3220"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/zstd/PYSEC-2023-121.yaml"
        },
        {
          "url": "https://github.com/sergey-dryabzhinsky/python-zstd/commit/c8a619aebdbd6b838fbfef6e19325a70f631a4c6"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2022-4899.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-1141.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C63HAGVLQA6FJNDCHR7CNZZL6VSLILB2"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C63HAGVLQA6FJNDCHR7CNZZL6VSLILB2/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JEHRBBYYTPA4DETOM5XAKGCP37NUTLOA"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JEHRBBYYTPA4DETOM5XAKGCP37NUTLOA/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QYLDK6ODVC4LJSDULLX6Q2YHTFOWABCN"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QYLDK6ODVC4LJSDULLX6Q2YHTFOWABCN/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4899"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230725-0005"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230725-0005/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-4899"
        }
      ],
      "published": "2023-03-31T20:15:07+00:00",
      "updated": "2026-06-17T05:22:14+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.4.4-1.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2023-0464",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        295
      ],
      "description": "A security vulnerability has been identified in all supported versions\n\nof OpenSSL related to the verification of X.509 certificate chains\nthat include policy constraints.  Attackers may be able to exploit this\nvulnerability by creating a malicious certificate chain that triggers\nexponential use of computational resources, leading to a denial-of-service\n(DoS) attack on affected systems.\n\nPolicy processing is disabled by default but can be enabled by passing\nthe `-policy' argument to the command line utilities or by calling the\n`X509_VERIFY_PARAM_set1_policies()' function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-0464"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2023:3722"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-0464"
        },
        {
          "url": "https://bugzilla.redhat.com/2181082"
        },
        {
          "url": "https://bugzilla.redhat.com/2182561"
        },
        {
          "url": "https://bugzilla.redhat.com/2182565"
        },
        {
          "url": "https://bugzilla.redhat.com/2188461"
        },
        {
          "url": "https://bugzilla.redhat.com/2207947"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2023-3722.html"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2017771e2db3e2b96f89bbe8766c3209f6a99545"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2dcd4f1e3115f38cefa43e3efbe9b801c27e642e"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=879f7080d7e141f415c79eaa3a8ac4a3dad0348b"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=959c59c7a0164117e7f8366466a32bb1f8d77ff1"
        },
        {
          "url": "https://github.com/advisories/GHSA-w2w6-xp88-5cvw"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-0464.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2023-3722.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0464"
        },
        {
          "url": "https://security.gentoo.org/glsa/202402-08"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230406-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230406-0006/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240621-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240621-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6039-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.couchbase.com/alerts"
        },
        {
          "url": "https://www.couchbase.com/alerts/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-0464"
        },
        {
          "url": "https://www.debian.org/security/2023/dsa-5417"
        },
        {
          "url": "https://www.openssl.org/news/secadv/20230322.txt"
        }
      ],
      "published": "2023-03-22T17:15:13+00:00",
      "updated": "2026-06-17T05:25:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2023-0465",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        295
      ],
      "description": "Applications that use a non-default option when verifying certificates may be\nvulnerable to an attack from a malicious CA to circumvent certain checks.\n\nInvalid certificate policies in leaf certificates are silently ignored by\nOpenSSL and other certificate policy checks are skipped for that certificate.\nA malicious CA could use this to deliberately assert invalid certificate policies\nin order to circumvent policy checking on the certificate altogether.\n\nPolicy processing is disabled by default but can be enabled by passing\nthe `-policy' argument to the command line utilities or by calling the\n`X509_VERIFY_PARAM_set1_policies()' function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-0465"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2023:3722"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-0465"
        },
        {
          "url": "https://bugzilla.redhat.com/2181082"
        },
        {
          "url": "https://bugzilla.redhat.com/2182561"
        },
        {
          "url": "https://bugzilla.redhat.com/2182565"
        },
        {
          "url": "https://bugzilla.redhat.com/2188461"
        },
        {
          "url": "https://bugzilla.redhat.com/2207947"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2023-3722.html"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=10325176f3d3e98c6e2b3bf5ab1e3b334de6947a"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1dd43e0709fece299b15208f36cc7c76209ba0bb"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=b013765abfa80036dc779dd0e50602c57bb3bf95"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=facfb1ab745646e97a1920977ae4a9965ea61d5c"
        },
        {
          "url": "https://github.com/advisories/GHSA-77f3-6546-6rj7"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-0465.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2023-3722.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0465"
        },
        {
          "url": "https://security.gentoo.org/glsa/202402-08"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230414-0001"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230414-0001/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6039-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-0465"
        },
        {
          "url": "https://www.debian.org/security/2023/dsa-5417"
        },
        {
          "url": "https://www.openssl.org/news/secadv/20230328.txt"
        }
      ],
      "published": "2023-03-28T15:15:06+00:00",
      "updated": "2026-06-17T05:25:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2023-0466",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        295
      ],
      "description": "The function X509_VERIFY_PARAM_add0_policy() is documented to\nimplicitly enable the certificate policy check when doing certificate\nverification. However the implementation of the function does not\nenable the check which allows certificates with invalid or incorrect\npolicies to pass the certificate verification.\n\nAs suddenly enabling the policy check could break existing deployments it was\ndecided to keep the existing behavior of the X509_VERIFY_PARAM_add0_policy()\nfunction.\n\nInstead the applications that require OpenSSL to perform certificate\npolicy check need to use X509_VERIFY_PARAM_set1_policies() or explicitly\nenable the policy check by calling X509_VERIFY_PARAM_set_flags() with\nthe X509_V_FLAG_POLICY_CHECK flag argument.\n\nCertificate policy checks are disabled by default in OpenSSL and are not\ncommonly used by applications.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-0466"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2023/09/28/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2023:3722"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-0466"
        },
        {
          "url": "https://bugzilla.redhat.com/2181082"
        },
        {
          "url": "https://bugzilla.redhat.com/2182561"
        },
        {
          "url": "https://bugzilla.redhat.com/2182565"
        },
        {
          "url": "https://bugzilla.redhat.com/2188461"
        },
        {
          "url": "https://bugzilla.redhat.com/2207947"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2023-3722.html"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=0d16b7e99aafc0b4a6d729eec65a411a7e025f0a"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=51e8a84ce742db0f6c70510d0159dad8f7825908"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=73398dea26de9899fb4baa94098ad0a61f435c72"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fc814a30fc4f0bc54fcea7d9a7462f5457aab061"
        },
        {
          "url": "https://github.com/advisories/GHSA-pxvj-4wx4-gv6w"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-0466.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2023-3722.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0466"
        },
        {
          "url": "https://security.gentoo.org/glsa/202402-08"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230414-0001"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230414-0001/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6039-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-0466"
        },
        {
          "url": "https://www.debian.org/security/2023/dsa-5417"
        },
        {
          "url": "https://www.openssl.org/news/secadv/20230328.txt"
        }
      ],
      "published": "2023-03-28T15:15:06+00:00",
      "updated": "2026-06-17T05:25:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2023-2650",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Issue summary: Processing some specially crafted ASN.1 object identifiers or\ndata containing them may be very slow.\n\nImpact summary: Applications that use OBJ_obj2txt() directly, or use any of\nthe OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message\nsize limit may experience notable to very long delays when processing those\nmessages, which may lead to a Denial of Service.\n\nAn OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers -\nmost of which have no size limit.  OBJ_obj2txt() may be used to translate\nan ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL\ntype ASN1_OBJECT) to its canonical numeric text form, which are the\nsub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by\nperiods.\n\nWhen one of the sub-identifiers in the OBJECT IDENTIFIER is very large\n(these are sizes that are seen as absurdly large, taking up tens or hundreds\nof KiBs), the translation to a decimal number in text may take a very long\ntime.  The time complexity is O(n^2) with 'n' being the size of the\nsub-identifiers in bytes (*).\n\nWith OpenSSL 3.0, support to fetch cryptographic algorithms using names /\nidentifiers in string form was introduced.  This includes using OBJECT\nIDENTIFIERs in canonical numeric text form as identifiers for fetching\nalgorithms.\n\nSuch OBJECT IDENTIFIERs may be received through the ASN.1 structure\nAlgorithmIdentifier, which is commonly used in multiple protocols to specify\nwhat cryptographic algorithm should be used to sign or verify, encrypt or\ndecrypt, or digest passed data.\n\nApplications that call OBJ_obj2txt() directly with untrusted data are\naffected, with any version of OpenSSL.  If the use is for the mere purpose\nof display, the severity is considered low.\n\nIn OpenSSL 3.0 and newer, this affects the subsystems OCSP, PKCS7/SMIME,\nCMS, CMP/CRMF or TS.  It also impacts anything that processes X.509\ncertificates, including simple things like verifying its signature.\n\nThe impact on TLS is relatively low, because all versions of OpenSSL have a\n100KiB limit on the peer's certificate chain.  Additionally, this only\nimpacts clients, or servers that have explicitly enabled client\nauthentication.\n\nIn OpenSSL 1.1.1 and 1.0.2, this only affects displaying diverse objects,\nsuch as X.509 certificates.  This is assumed to not happen in such a way\nthat it would cause a Denial of Service, so these versions are considered\nnot affected by this issue in such a way that it would be cause for concern,\nand the severity is therefore considered low.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-2650"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2023/05/30/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2023:6330"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-2650"
        },
        {
          "url": "https://bugzilla.redhat.com/1858038"
        },
        {
          "url": "https://bugzilla.redhat.com/2207947"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2023-6330.html"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=423a2bc737a908ad0c77bda470b2b59dc879936b"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=853c5e56ee0b8650c73140816bb8b91d6163422c"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9e209944b35cf82368071f160a744b6178f9b098"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db779b0e10b047f2585615e0b8f2acdf21f8544a"
        },
        {
          "url": "https://github.com/advisories/GHSA-gqxg-9vfr-p9cg"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-2650.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2023-6330.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2650"
        },
        {
          "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0009"
        },
        {
          "url": "https://security.gentoo.org/glsa/202402-08"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230703-0001/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231027-0009/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6119-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6188-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6672-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-2650"
        },
        {
          "url": "https://www.debian.org/security/2023/dsa-5417"
        },
        {
          "url": "https://www.openssl.org/news/secadv/20230530.txt"
        }
      ],
      "published": "2023-05-30T14:15:09+00:00",
      "updated": "2026-06-17T05:53:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2023-27534",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        22
      ],
      "description": "A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-27534"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2023:6679"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-27534"
        },
        {
          "url": "https://bugzilla.redhat.com/2179062"
        },
        {
          "url": "https://bugzilla.redhat.com/2179069"
        },
        {
          "url": "https://bugzilla.redhat.com/2179092"
        },
        {
          "url": "https://bugzilla.redhat.com/2179103"
        },
        {
          "url": "https://curl.se/docs/CVE-2023-27534.html"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2023-6679.html"
        },
        {
          "url": "https://hackerone.com/reports/1892351"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-27534.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2023-6679.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00016.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27534"
        },
        {
          "url": "https://security.gentoo.org/glsa/202310-12"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230420-0012/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5964-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-27534"
        }
      ],
      "published": "2023-03-30T20:15:07+00:00",
      "updated": "2026-06-17T05:45:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2023-29499",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-29499"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2528"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-29499"
        },
        {
          "url": "https://bugzilla.redhat.com/2211827"
        },
        {
          "url": "https://bugzilla.redhat.com/2211828"
        },
        {
          "url": "https://bugzilla.redhat.com/2211829"
        },
        {
          "url": "https://bugzilla.redhat.com/2211833"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2211828"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2528.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/2794"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-29499.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2528.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00030.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29499"
        },
        {
          "url": "https://security.gentoo.org/glsa/202311-18"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231103-0001/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-29499"
        }
      ],
      "published": "2023-09-14T20:15:09+00:00",
      "updated": "2026-06-17T05:50:13+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-177.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2023-32611",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-32611"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2528"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-32611"
        },
        {
          "url": "https://bugzilla.redhat.com/2211827"
        },
        {
          "url": "https://bugzilla.redhat.com/2211828"
        },
        {
          "url": "https://bugzilla.redhat.com/2211829"
        },
        {
          "url": "https://bugzilla.redhat.com/2211833"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2211829"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2528.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/2797"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-32611.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2528.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00030.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32611"
        },
        {
          "url": "https://security.gentoo.org/glsa/202311-18"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231027-0005/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-32611"
        }
      ],
      "published": "2023-09-14T20:15:09+00:00",
      "updated": "2026-06-23T18:17:32+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-177.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2023-32636",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400,
        502
      ],
      "description": "A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-32636"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2528"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-32636"
        },
        {
          "url": "https://bugzilla.redhat.com/2211827"
        },
        {
          "url": "https://bugzilla.redhat.com/2211828"
        },
        {
          "url": "https://bugzilla.redhat.com/2211829"
        },
        {
          "url": "https://bugzilla.redhat.com/2211833"
        },
        {
          "url": "https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2528.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/2841"
        },
        {
          "url": "https://https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-32636.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2528.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32636"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231110-0002/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-32636"
        }
      ],
      "published": "2023-09-14T20:15:09+00:00",
      "updated": "2026-06-17T05:59:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-177.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-32665",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400,
        502
      ],
      "description": "A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-32665"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2528"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-32665"
        },
        {
          "url": "https://bugzilla.redhat.com/2211827"
        },
        {
          "url": "https://bugzilla.redhat.com/2211828"
        },
        {
          "url": "https://bugzilla.redhat.com/2211829"
        },
        {
          "url": "https://bugzilla.redhat.com/2211833"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2211827"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2528.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/2121"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-32665.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2528.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00030.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32665"
        },
        {
          "url": "https://security.gentoo.org/glsa/202311-18"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240426-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-32665"
        }
      ],
      "published": "2023-09-14T20:15:09+00:00",
      "updated": "2026-06-17T05:59:20+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-177.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2023-39804",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-39804"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-39804"
        },
        {
          "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1058079"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/tar.git/commit/?id=a339f05cd269013fa133d2f148d73f6f7d4247e4"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/tar.git/tree/src/xheader.c?h=release_1_34#n1723"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00008.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39804"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-39804"
        }
      ],
      "published": "2024-03-27T04:15:08+00:00",
      "updated": "2026-06-17T06:12:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-4156",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-4156"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-4156"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2215930"
        },
        {
          "url": "https://git.savannah.gnu.org/gitweb/?p=gawk.git;a=commitdiff;h=e709eb829448ce040087a3fc5481db6bfcaae212"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-gawk/2022-08/msg00000.html"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-gawk/2022-08/msg00023.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4156"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6373-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-4156"
        }
      ],
      "published": "2023-09-25T18:15:11+00:00",
      "updated": "2026-06-17T06:37:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.2.1-4.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-45322",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is \"I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail.\"",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-45322"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2023/10/06/5"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-45322"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/344"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/583"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45322"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-45322"
        }
      ],
      "published": "2023-10-06T22:15:11+00:00",
      "updated": "2026-06-17T06:28:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-45803",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        200
      ],
      "description": "urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs. Although this behavior is not specified in the section for redirects, it can be inferred by piecing together information from different sections and we have observed the behavior in other major HTTP client implementations like curl and web browsers. Because the vulnerability requires a previously trusted service to become compromised in order to have an impact on confidentiality we believe the exploitability of this vulnerability is low. Additionally, many users aren't putting sensitive data in HTTP request bodies, if this is the case then this vulnerability isn't exploitable. Both of the following conditions must be true to be affected by this vulnerability: 1. Using urllib3 and submitting sensitive information in the HTTP request body (such as form data or JSON) and 2. The origin service is compromised and starts redirecting using 301, 302, or 303 to a malicious peer or the redirected-to service becomes compromised. This issue has been addressed in versions 1.26.18 and 2.0.7 and users are advised to update to resolve this issue. Users unable to update should disable redirects for services that aren't expecting to respond with redirects with `redirects=False` and disable automatic redirects with `redirects=False` and handle 301, 302, and 303 redirects manually by stripping the HTTP request body.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-45803"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:11238"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2132"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-45803"
        },
        {
          "url": "https://bugzilla.redhat.com/2246840"
        },
        {
          "url": "https://bugzilla.redhat.com/2257028"
        },
        {
          "url": "https://bugzilla.redhat.com/2257854"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2246840"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45803"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2132.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2024:11238"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2023-212.yaml"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/4e50fbc5db74e32cabd5ccc1ab81fc103adfe0b3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/4e98d57809dacab1cbe625fddeec1a290c478ea9"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/b594c5ceaca38e1ac215f916538fb128e3526a36"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/1.26.18"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.0.7"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-g4mx-q9vg-27p4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-45803.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2988.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00020.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4R2Y5XK3WALSR3FNAGN7JBYV2B343ZKB"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4R2Y5XK3WALSR3FNAGN7JBYV2B343ZKB/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PPDPLM6UUMN55ESPQWJFLLIZY4ZKCNRX"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PPDPLM6UUMN55ESPQWJFLLIZY4ZKCNRX/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45803"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6473-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6473-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7762-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-45803"
        },
        {
          "url": "https://www.rfc-editor.org/rfc/rfc9110.html#name-get"
        }
      ],
      "published": "2023-10-17T20:15:10+00:00",
      "updated": "2026-06-17T06:29:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-50495",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-50495"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-50495"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50495"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240119-0008/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6684-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-50495"
        }
      ],
      "published": "2023-12-12T15:15:07+00:00",
      "updated": "2026-06-17T06:39:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-0232",
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-0232"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-0232"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2243754"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0232"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240315-0007/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-0232"
        }
      ],
      "published": "2024-01-16T14:15:48+00:00",
      "updated": "2026-06-17T06:53:02+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.26.0-21.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-0397",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        362
      ],
      "description": "A defect was discovered in the Python \u201cssl\u201d module where there is a memory\nrace condition with the ssl.SSLContext methods \u201ccert_store_stats()\u201d and\n\u201cget_ca_certs()\u201d. The race condition can be triggered if the methods are\ncalled at the same time as certificates are loaded into the SSLContext,\nsuch as during the TLS handshake with a certificate directory configured.\nThis issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-0397"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/06/17/2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-0397"
        },
        {
          "url": "https://github.com/python/cpython/commit/01c37f1d0714f5822d34063ca7180b595abf589d"
        },
        {
          "url": "https://github.com/python/cpython/commit/29c97287d205bf2f410f4895ebce3f43b5160524"
        },
        {
          "url": "https://github.com/python/cpython/commit/37324b421b72b7bc9934e27aba85d48d4773002e"
        },
        {
          "url": "https://github.com/python/cpython/commit/542f3272f56f31ed04e74c40635a913fbc12d286"
        },
        {
          "url": "https://github.com/python/cpython/commit/b228655c227b2ca298a8ffac44d14ce3d22f6faa"
        },
        {
          "url": "https://github.com/python/cpython/commit/bce693111bff906ccf9281c22371331aaff766ab"
        },
        {
          "url": "https://github.com/python/cpython/commit/bce693111bff906ccf9281c22371331aaff766ab%20%283.13%29"
        },
        {
          "url": "https://github.com/python/cpython/issues/114572"
        },
        {
          "url": "https://github.com/python/cpython/pull/114573"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/BMAK5BCGKYWNJOACVUSLUF6SFGBIM4VP/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0397"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250411-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6928-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-0397"
        }
      ],
      "published": "2024-06-17T16:15:10+00:00",
      "updated": "2026-06-17T06:53:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ]
    },
    {
      "id": "CVE-2024-0727",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL\nto crash leading to a potential Denial of Service attack\n\nImpact summary: Applications loading files in the PKCS12 format from untrusted\nsources might terminate abruptly.\n\nA file in PKCS12 format can contain certificates and keys and may come from an\nuntrusted source. The PKCS12 specification allows certain fields to be NULL, but\nOpenSSL does not correctly check for this case. This can lead to a NULL pointer\ndereference that results in OpenSSL crashing. If an application processes PKCS12\nfiles from an untrusted source using the OpenSSL APIs then that application will\nbe vulnerable to this issue.\n\nOpenSSL APIs that are vulnerable to this are: PKCS12_parse(),\nPKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes()\nand PKCS12_newpass().\n\nWe have also fixed a similar issue in SMIME_write_PKCS7(). However since this\nfunction is related to writing data we do not consider it security significant.\n\nThe FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-0727"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/03/11/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:9088"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-0727"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2024-0727"
        },
        {
          "url": "https://bugzilla.redhat.com/2257571"
        },
        {
          "url": "https://bugzilla.redhat.com/2258502"
        },
        {
          "url": "https://bugzilla.redhat.com/2259944"
        },
        {
          "url": "https://bugzilla.redhat.com/2284243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2257571"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258502"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2259944"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2284243"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-277137.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-331112.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-769027.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-915275.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6129"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6237"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0727"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1298"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-9088.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2024:9088"
        },
        {
          "url": "https://github.com/advisories/GHSA-9v9h-cgj8-h64p"
        },
        {
          "url": "https://github.com/alexcrichton/openssl-src-rs/commit/add20f73b6b42be7451af2e1044d4e0e778992b2"
        },
        {
          "url": "https://github.com/github/advisory-database/pull/3472"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/09df4395b5071217b76dc7d3d2e630eb8c5a79c2"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/775acfdbd0c6af9ac855f34969cdab0c0c90844a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d135eeab8a5dbf72b3da5240bab9ddb7678dbd2c"
        },
        {
          "url": "https://github.com/openssl/openssl/pull/23362"
        },
        {
          "url": "https://github.com/pyca/cryptography/commit/3519591d255d4506fbcd0d04037d45271903c64d"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/03b3941d60c4bce58fab69a0c22377ab439bc0e8"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/aebaa5883e31122b404e450732dc833dc9dee539"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-0727.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-9088.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0727"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240208-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240208-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6622-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6632-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6709-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7018-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-0727"
        },
        {
          "url": "https://www.openssl.org/news/secadv/20240125.txt"
        }
      ],
      "published": "2024-01-26T09:15:07+00:00",
      "updated": "2026-06-17T06:54:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any Python code. That assures that the vulnerable code path in the affected library is not reachable. The Python libraries are only used for diagnostics."
      }
    },
    {
      "id": "CVE-2024-10524",
      "ratings": [
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        918
      ],
      "description": "Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-10524"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/11/18/6"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-10524"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/wget.git/commit/?id=c419542d956a2607bbce5df64b9d378a8588d778"
        },
        {
          "url": "https://github.com/advisories/GHSA-mqrm-h2pw-9j9r"
        },
        {
          "url": "https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability"
        },
        {
          "url": "https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10524"
        },
        {
          "url": "https://seclists.org/oss-sec/2024/q4/107"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250321-0007"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250321-0007/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-10524"
        }
      ],
      "published": "2024-11-19T15:15:06+00:00",
      "updated": "2026-06-17T06:55:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.19.5-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-11053",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has an entry that matches\nthe redirect target hostname but the entry either omits just the password or\nomits both login and password.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-11053"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/12/11/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:1671"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-11053"
        },
        {
          "url": "https://bugzilla.redhat.com/2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/2339305"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339305"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-11053.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-11053.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21193"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21194"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21196"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21197"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21198"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21201"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21203"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21212"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21213"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21218"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21219"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21230"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21231"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21236"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21237"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21238"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21239"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21241"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21247"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37371"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5535"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7264"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21490"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21491"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21494"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21497"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21500"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21501"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21503"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21505"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21518"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21520"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21521"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21522"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21523"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21525"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21529"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21531"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21534"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21536"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21540"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21543"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21546"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21555"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21559"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-1671.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:1671"
        },
        {
          "url": "https://github.com/advisories/GHSA-h288-5fq8-5pfw"
        },
        {
          "url": "https://hackerone.com/reports/2829063"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-11053.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-1673.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11053"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0012"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0012/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0003"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0003/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0004"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0004/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7162-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-11053"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpujan2025.html#AppendixMSQL"
        }
      ],
      "published": "2024-12-11T08:15:05+00:00",
      "updated": "2026-06-17T06:56:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-13176",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        385
      ],
      "description": "Issue summary: A timing side-channel which could potentially allow recovering\nthe private key exists in the ECDSA signature computation.\n\nImpact summary: A timing side-channel in ECDSA signature computations\ncould allow recovering the private key by an attacker. However, measuring\nthe timing would require either local access to the signing application or\na very fast network connection with low latency.\n\nThere is a timing signal of around 300 nanoseconds when the top word of\nthe inverted ECDSA nonce value is zero. This can happen with significant\nprobability only for some of the supported elliptic curves. In particular\nthe NIST P-521 curve is affected. To be able to measure this leak, the attacker\nprocess must either be located in the same physical computer or must\nhave a very fast network connection with low latency. For that reason\nthe severity of this vulnerability is Low.\n\nThe FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-13176"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/01/20/2"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:15699"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:16046"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-13176"
        },
        {
          "url": "https://bugzilla.redhat.com/2359885"
        },
        {
          "url": "https://bugzilla.redhat.com/2359888"
        },
        {
          "url": "https://bugzilla.redhat.com/2359892"
        },
        {
          "url": "https://bugzilla.redhat.com/2359894"
        },
        {
          "url": "https://bugzilla.redhat.com/2359895"
        },
        {
          "url": "https://bugzilla.redhat.com/2359899"
        },
        {
          "url": "https://bugzilla.redhat.com/2359900"
        },
        {
          "url": "https://bugzilla.redhat.com/2359902"
        },
        {
          "url": "https://bugzilla.redhat.com/2359903"
        },
        {
          "url": "https://bugzilla.redhat.com/2359911"
        },
        {
          "url": "https://bugzilla.redhat.com/2359918"
        },
        {
          "url": "https://bugzilla.redhat.com/2359920"
        },
        {
          "url": "https://bugzilla.redhat.com/2359924"
        },
        {
          "url": "https://bugzilla.redhat.com/2359928"
        },
        {
          "url": "https://bugzilla.redhat.com/2359930"
        },
        {
          "url": "https://bugzilla.redhat.com/2359932"
        },
        {
          "url": "https://bugzilla.redhat.com/2359934"
        },
        {
          "url": "https://bugzilla.redhat.com/2359938"
        },
        {
          "url": "https://bugzilla.redhat.com/2359940"
        },
        {
          "url": "https://bugzilla.redhat.com/2359943"
        },
        {
          "url": "https://bugzilla.redhat.com/2359944"
        },
        {
          "url": "https://bugzilla.redhat.com/2359945"
        },
        {
          "url": "https://bugzilla.redhat.com/2359947"
        },
        {
          "url": "https://bugzilla.redhat.com/2359950"
        },
        {
          "url": "https://bugzilla.redhat.com/2359963"
        },
        {
          "url": "https://bugzilla.redhat.com/2359964"
        },
        {
          "url": "https://bugzilla.redhat.com/2359972"
        },
        {
          "url": "https://bugzilla.redhat.com/2370920"
        },
        {
          "url": "https://bugzilla.redhat.com/2380264"
        },
        {
          "url": "https://bugzilla.redhat.com/2380273"
        },
        {
          "url": "https://bugzilla.redhat.com/2380274"
        },
        {
          "url": "https://bugzilla.redhat.com/2380278"
        },
        {
          "url": "https://bugzilla.redhat.com/2380280"
        },
        {
          "url": "https://bugzilla.redhat.com/2380283"
        },
        {
          "url": "https://bugzilla.redhat.com/2380284"
        },
        {
          "url": "https://bugzilla.redhat.com/2380290"
        },
        {
          "url": "https://bugzilla.redhat.com/2380291"
        },
        {
          "url": "https://bugzilla.redhat.com/2380295"
        },
        {
          "url": "https://bugzilla.redhat.com/2380298"
        },
        {
          "url": "https://bugzilla.redhat.com/2380306"
        },
        {
          "url": "https://bugzilla.redhat.com/2380308"
        },
        {
          "url": "https://bugzilla.redhat.com/2380309"
        },
        {
          "url": "https://bugzilla.redhat.com/2380310"
        },
        {
          "url": "https://bugzilla.redhat.com/2380312"
        },
        {
          "url": "https://bugzilla.redhat.com/2380313"
        },
        {
          "url": "https://bugzilla.redhat.com/2380320"
        },
        {
          "url": "https://bugzilla.redhat.com/2380321"
        },
        {
          "url": "https://bugzilla.redhat.com/2380322"
        },
        {
          "url": "https://bugzilla.redhat.com/2380326"
        },
        {
          "url": "https://bugzilla.redhat.com/2380327"
        },
        {
          "url": "https://bugzilla.redhat.com/2380334"
        },
        {
          "url": "https://bugzilla.redhat.com/2380335"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2338999"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359895"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359899"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359902"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359903"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359911"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359918"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359920"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359924"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359928"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359930"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359934"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359938"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359940"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359943"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359944"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359945"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359947"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359950"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359963"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359964"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359972"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370920"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380264"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380273"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380274"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380278"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380280"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380283"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380290"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380298"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380306"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380308"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380309"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380310"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380312"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380313"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380320"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380321"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380322"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380326"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380327"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380334"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380335"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-13176"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21574"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21575"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21577"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21579"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21580"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21581"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21584"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21585"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30681"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30682"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30683"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30684"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30685"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30687"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30688"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30689"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30693"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30695"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30696"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30699"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30703"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30704"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30705"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30715"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30721"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30722"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50077"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50078"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50079"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50080"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50081"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50082"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50083"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50084"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50085"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50086"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50087"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50088"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50091"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50092"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50093"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50094"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50096"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50097"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50098"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50099"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50100"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50101"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50102"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50104"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5399"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-16046.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:15699"
        },
        {
          "url": "https://github.com/advisories/GHSA-r9fv-h47r-823f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/07272b05b04836a762b4baa874958af51d513844"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2af62e74fb59bc469506bc37eb2990ea408d9467"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/392dcb336405a0c94486aa6655057f59fd3a0902"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4b1cb94a734a7d4ec363ac0a215a25c181e11f65"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/77c608f4c8857e63e98e66444e2e761c9627916f"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/0d5fd1ab987f7571e2c955d8d8b638fc0fb54ded"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/a2639000db19878d5d89586ae7b725080592ae86"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-13176.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-16046.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13176"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20250120.txt"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0005"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0005/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250418-0010"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250418-0010/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250502-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250502-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7264-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7278-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-13176"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2025.html#AppendixMSQL"
        }
      ],
      "published": "2025-01-20T14:15:26+00:00",
      "updated": "2026-06-17T07:01:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-2236",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        385
      ],
      "description": "A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-2236"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:9404"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:3530"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:3534"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-2236"
        },
        {
          "url": "https://bugzilla.redhat.com/2245218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2268268"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2236"
        },
        {
          "url": "https://dev.gnupg.org/T7136"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-9404.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2024:9404"
        },
        {
          "url": "https://github.com/tomato42/marvin-toolkit/tree/master/example/libgcrypt"
        },
        {
          "url": "https://gitlab.com/redhat-crypto/libgcrypt/libgcrypt-mirror/-/merge_requests/17"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-2236.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-9404.html"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gcrypt-devel/2024-March/005607.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2236"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8711-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-2236"
        }
      ],
      "published": "2024-03-06T22:15:57+00:00",
      "updated": "2026-06-17T07:24:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.8.5-8.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2024-2511",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        1325
      ],
      "description": "Issue summary: Some non-default TLS server configurations can cause unbounded\nmemory growth when processing TLSv1.3 sessions\n\nImpact summary: An attacker may exploit certain server configurations to trigger\nunbounded memory growth that would lead to a Denial of Service\n\nThis problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is\nbeing used (but not if early_data support is also configured and the default\nanti-replay protection is in use). In this case, under certain conditions, the\nsession cache can get into an incorrect state and it will fail to flush properly\nas it fills. The session cache will continue to grow in an unbounded manner. A\nmalicious client could deliberately create the scenario for this failure to\nforce a Denial of Service. It may also happen by accident in normal operation.\n\nThis issue only affects TLS servers supporting TLSv1.3. It does not affect TLS\nclients.\n\nThe FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL\n1.0.2 is also not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-2511"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/04/08/5"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:9333"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-2511"
        },
        {
          "url": "https://bugzilla.redhat.com/2274020"
        },
        {
          "url": "https://bugzilla.redhat.com/2281029"
        },
        {
          "url": "https://bugzilla.redhat.com/2283757"
        },
        {
          "url": "https://bugzilla.redhat.com/2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2274020"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2281029"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2283757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294581"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-354112.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-398330.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-613116.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-769027.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-915275.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2511"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4603"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4741"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5535"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-9333.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2024:9333"
        },
        {
          "url": "https://github.com/advisories/GHSA-299c-jvhc-gxj8"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/e9d7083e241670332e0443da0f0d4ffb52829f08"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/5f8d25770ae6437db119dfc951e207271a326640"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-2511.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-9333.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2511"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240503-0013"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240503-0013/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6937-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-2511"
        },
        {
          "url": "https://www.openssl.org/news/secadv/20240408.txt"
        },
        {
          "url": "https://www.openssl.org/news/vulnerabilities.html"
        }
      ],
      "published": "2024-04-08T14:15:07+00:00",
      "updated": "2026-06-17T07:24:40+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2024-25260",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-25260"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-25260"
        },
        {
          "url": "https://github.com/schsiung/fuzzer_issues/issues/1"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25260"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=31058"
        },
        {
          "url": "https://sourceware.org/elfutils/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7369-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-25260"
        }
      ],
      "published": "2024-02-20T18:15:52+00:00",
      "updated": "2026-06-17T07:15:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.190-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.190-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.190-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-33655",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        400
      ],
      "description": "The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the \"DNSBomb\" issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-33655"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18931"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-33655"
        },
        {
          "url": "https://alas.aws.amazon.com/ALAS-2024-1934.html"
        },
        {
          "url": "https://bugzilla.redhat.com/2279942"
        },
        {
          "url": "https://bugzilla.redhat.com/2405706"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2279942"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2405706"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-33655"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11411"
        },
        {
          "url": "https://datatracker.ietf.org/doc/html/rfc1035"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-18931.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18931"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/commit/c3206f4568f60c486be6d165b1f2b5b254fea3de"
        },
        {
          "url": "https://github.com/TechnitiumSoftware/DnsServer/blob/master/CHANGELOG.md#version-120"
        },
        {
          "url": "https://gitlab.isc.org/isc-projects/bind9/-/issues/4398"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-33655.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18931.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/08/msg00019.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3TBXPRJ2Q235YUZKYDRWOSYNDFBJQWJ3/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QITY2QBX2OCBTZIXD2A5ES62STFIA4AL/"
        },
        {
          "url": "https://meterpreter.org/researchers-uncover-dnsbomb-a-new-pdos-attack-exploiting-legitimate-dns-features/"
        },
        {
          "url": "https://nlnetlabs.nl/downloads/unbound/CVE-2024-33655.txt"
        },
        {
          "url": "https://nlnetlabs.nl/projects/unbound/security-advisories/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33655"
        },
        {
          "url": "https://sp2024.ieee-security.org/accepted-papers.html"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6791-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-33655"
        },
        {
          "url": "https://www.isc.org/blogs/2024-dnsbomb/"
        },
        {
          "url": "https://www.nlnetlabs.nl/news/2024/May/08/unbound-1.20.0-released/"
        }
      ],
      "published": "2024-06-06T17:15:51+00:00",
      "updated": "2026-06-17T07:32:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2024-41996",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        295
      ],
      "description": "Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-41996"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-41996"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-089022.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-485750.html"
        },
        {
          "url": "https://dheatattack.gitlab.io/details/"
        },
        {
          "url": "https://dheatattack.gitlab.io/faq/"
        },
        {
          "url": "https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1"
        },
        {
          "url": "https://github.com/openssl/openssl/issues/17374"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41996"
        },
        {
          "url": "https://openssl-library.org/post/2022-10-21-tls-groups-configuration/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-41996"
        }
      ],
      "published": "2024-08-26T06:15:04+00:00",
      "updated": "2026-06-17T07:48:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-43167",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made a claim that there is a security risk within Red Hat products. NLnet Labs has no further information about the claim, and suggests that affected Red Hat customers refer to available Red Hat documentation or support channels. ORIGINAL DESCRIPTION: A NULL pointer dereference flaw was found in the ub_ctx_set_fwd function in Unbound. This issue could allow an attacker who can invoke specific sequences of API calls to cause a segmentation fault. When certain API functions such as ub_ctx_set_fwd and ub_ctx_resolvconf are called in a particular order, the program attempts to read from a NULL pointer, leading to a crash. This issue can result in a denial of service by causing the application to terminate unexpectedly.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-43167"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/08/16/6"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-43167"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2303456"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/issues/1072"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/pull/1073"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/pull/1073/files"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00046.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43167"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6998-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-43167"
        }
      ],
      "published": "2024-08-12T13:38:35+00:00",
      "updated": "2026-06-17T07:50:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2024-43168",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made a claim that there is a security risk within Red Hat products. NLnet Labs has no further information about the claim, and suggests that affected Red Hat customers refer to available Red Hat documentation or support channels. ORIGINAL DESCRIPTION: A heap-buffer-overflow flaw was found in the cfg_mark_ports function within Unbound's config_file.c, which can lead to memory corruption. This issue could allow an attacker with local access to provide specially crafted input, potentially causing the application to crash or allowing arbitrary code execution. This could result in a denial of service or unauthorized actions on the system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-43168"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-43168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2303462"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/issues/1039"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/pull/1040"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/pull/1040/files"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00046.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43168"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6998-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-43168"
        }
      ],
      "published": "2024-08-12T13:38:36+00:00",
      "updated": "2026-06-17T07:50:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2024-56433",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.6,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        1188
      ],
      "description": "shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-56433"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:20559"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-56433"
        },
        {
          "url": "https://bugzilla.redhat.com/2334165"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2334165"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-56433"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-20559.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:20559"
        },
        {
          "url": "https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241"
        },
        {
          "url": "https://github.com/shadow-maint/shadow/issues/1157"
        },
        {
          "url": "https://github.com/shadow-maint/shadow/releases/tag/4.4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-56433.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-20559-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56433"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-56433"
        }
      ],
      "published": "2024-12-26T09:15:07+00:00",
      "updated": "2026-06-17T08:12:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:4.6-23.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2024-57970",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        126
      ],
      "description": "libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-57970"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:7510"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-57970"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345954"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-57970"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:7510"
        },
        {
          "url": "https://github.com/advisories/GHSA-2q66-6w43-8rm9"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/2415"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2422"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-57970.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-7510.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57970"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-57970"
        }
      ],
      "published": "2025-02-16T04:15:21+00:00",
      "updated": "2026-06-17T08:14:20+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2024-7264",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an\nASN.1 Generalized Time field. If given an syntactically incorrect field, the\nparser might end up using -1 for the length of the *time fraction*, leading to\na `strlen()` getting performed on a pointer to a heap buffer area that is not\n(purposely) null terminated.\n\nThis flaw most likely leads to a crash, but can also lead to heap contents\ngetting returned to the application when\n[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-7264"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/07/31/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:1671"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-7264"
        },
        {
          "url": "https://bugzilla.redhat.com/2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/2339305"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339305"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-7264.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-7264.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21193"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21194"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21196"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21197"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21198"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21201"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21203"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21212"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21213"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21218"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21219"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21230"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21231"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21236"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21237"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21238"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21239"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21241"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21247"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37371"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5535"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7264"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21490"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21491"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21494"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21497"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21500"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21501"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21503"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21505"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21518"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21520"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21521"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21522"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21523"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21525"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21529"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21531"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21534"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21536"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21540"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21543"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21546"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21555"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21559"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-1671.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:1671"
        },
        {
          "url": "https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519"
        },
        {
          "url": "https://hackerone.com/reports/2629968"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-7264.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-1673.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7264"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240828-0008/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241025-0006/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241025-0010/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6944-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6944-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-7264"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuoct2024.html#AppendixMSQL"
        }
      ],
      "published": "2024-07-31T08:15:02+00:00",
      "updated": "2026-06-17T08:19:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-7592",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        400,
        1333
      ],
      "description": "There is a LOW severity vulnerability affecting CPython, specifically the\n'http.cookies' standard library module.\n\n\nWhen parsing cookies that contained backslashes for quoted characters in\nthe cookie value, the parser would use an algorithm with quadratic\ncomplexity, resulting in excess CPU resources being used while parsing the\nvalue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-7592"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:3634"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-7592"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2305879"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7592"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-3634.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:3634"
        },
        {
          "url": "https://github.com/python/cpython/commit/391e5626e3ee5af267b97e37abc7475732e67621"
        },
        {
          "url": "https://github.com/python/cpython/commit/44e458357fca05ca0ae2658d62c8c595b048b5ef"
        },
        {
          "url": "https://github.com/python/cpython/commit/a77ab24427a18bff817025adb03ca920dc3f1a06"
        },
        {
          "url": "https://github.com/python/cpython/commit/b2f11ca7667e4d57c71c1c88b255115f16042d9a"
        },
        {
          "url": "https://github.com/python/cpython/commit/d4ac921a4b081f7f996a5d2b101684b67ba0ed7f"
        },
        {
          "url": "https://github.com/python/cpython/commit/d662e2db2605515a767f88ad48096b8ac623c774"
        },
        {
          "url": "https://github.com/python/cpython/commit/dcc3eaef98cd94d6cb6cb0f44bd1c903d04f33b1"
        },
        {
          "url": "https://github.com/python/cpython/issues/123067"
        },
        {
          "url": "https://github.com/python/cpython/pull/123075"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-7592.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-3634.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/HXJAAAALNUNGCQUS2W7WR6GFIZIHFOOK/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7592"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241018-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7015-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7015-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-7592"
        }
      ],
      "published": "2024-08-19T19:15:08+00:00",
      "updated": "2026-06-17T08:20:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Temurin JVM binary is not linked against freetype library:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\nlinux-vdso.so.1 (0x0000ffff8cd00000)\nlibjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\nlibpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\nlibdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\nlibc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n/lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-11411",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        349
      ],
      "description": "NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their delegation information for the zone. Usually these RRSets are used to update the resolver's knowledge of the zone's name servers. A malicious actor can exploit the possible poisonous effect by injecting NS RRSets (and possibly their respective address records) in a reply. This could be done for example by trying to spoof a packet or fragmentation attacks. Unbound would then proceed to update the NS RRSet data it already has since the new data has enough trust for it, i.e., in-zone data for the delegation point. Unbound 1.24.1 includes a fix that scrubs unsolicited NS RRSets (and their respective address records) from replies mitigating the possible poison effect. Unbound 1.24.2 includes an additional fix that scrubs unsolicited NS RRSets (and their respective address records) from YXDOMAIN and non-referral nodata replies, further mitigating the possible poison effect.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-11411"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/11/26/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18931"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-11411"
        },
        {
          "url": "https://bugzilla.redhat.com/2279942"
        },
        {
          "url": "https://bugzilla.redhat.com/2405706"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2279942"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2405706"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-33655"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11411"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-18931.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18931"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-11411.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18931.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/11/msg00008.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/11/msg00032.html"
        },
        {
          "url": "https://nlnetlabs.nl/news/2025/Nov/26/unbound-1.24.2-released/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11411"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7855-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7855-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-11411"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2025-11411.txt"
        }
      ],
      "published": "2025-10-22T13:15:29+00:00",
      "updated": "2026-10-08T11:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-11468",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-11468"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-11468"
        },
        {
          "url": "https://github.com/python/cpython/commit/003b8315669b9f08b1010a49071f73f15f818094"
        },
        {
          "url": "https://github.com/python/cpython/commit/17d1490aa97bd6b98a42b1a9b324ead84e7fd8a2"
        },
        {
          "url": "https://github.com/python/cpython/commit/61614a5e5056e4f61ced65008d4576f3df34acb6"
        },
        {
          "url": "https://github.com/python/cpython/commit/a76e4cd62dd68e7cbe86e37e6ed988495a646b66"
        },
        {
          "url": "https://github.com/python/cpython/commit/e9970f077240c7c670e8a6fc6662f2b30d3b6ad0"
        },
        {
          "url": "https://github.com/python/cpython/commit/f738386838021c762efea6c9802c82de65e87796"
        },
        {
          "url": "https://github.com/python/cpython/issues/143935"
        },
        {
          "url": "https://github.com/python/cpython/pull/143936"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/FELSEOLBI2QR6YLG6Q7VYF7FWSGQTKLI/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11468"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-11468"
        }
      ],
      "published": "2026-01-20T22:15:50+00:00",
      "updated": "2026-06-17T08:30:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-11961",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 1.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        122,
        126
      ],
      "description": "pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer.  The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented.  If an application calls the function with an argument that deviates from the expected format, the function can read data beyond the end of the provided string and write data beyond the end of the allocated buffer.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-11961"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-11961"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/b2d2f9a9a0581c40780bde509f7cc715920f1c02"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11961"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-11961"
        }
      ],
      "published": "2025-12-31T01:15:54+00:00",
      "updated": "2026-06-17T08:31:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14",
          "versions": [
            {
              "version": "14:1.9.1-5.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-12781",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        704
      ],
      "description": "When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python.\u00a0Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-12781"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-12781"
        },
        {
          "url": "https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b"
        },
        {
          "url": "https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947"
        },
        {
          "url": "https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5"
        },
        {
          "url": "https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76"
        },
        {
          "url": "https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5"
        },
        {
          "url": "https://github.com/python/cpython/issues/125346"
        },
        {
          "url": "https://github.com/python/cpython/pull/141128"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-12781"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-12781"
        }
      ],
      "published": "2026-01-21T20:16:04+00:00",
      "updated": "2026-06-17T08:32:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13034",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        295
      ],
      "description": "When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool, curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13034"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13034"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-13034.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-13034.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-9r76-qj98-jfhc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13034"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13034"
        }
      ],
      "published": "2026-01-08T10:15:45+00:00",
      "updated": "2026-09-15T07:16:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13462",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        20,
        74,
        434
      ],
      "description": "The \"tarfile\" module would still apply normalization of AREGTYPE (\\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13462"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13462"
        },
        {
          "url": "https://github.com/python/cpython/commit/42d754e34c06e57ad6b8e7f92f32af679912d8ab"
        },
        {
          "url": "https://github.com/python/cpython/commit/72dde1016493c52abe857fc4a7bf6c40138b4114"
        },
        {
          "url": "https://github.com/python/cpython/commit/7ad3093d76a748af55bdb1d2e8aad3638163b017"
        },
        {
          "url": "https://github.com/python/cpython/commit/9a23b753552afa28e3a2f4d8863572fc66479406"
        },
        {
          "url": "https://github.com/python/cpython/commit/ae99fe3a33b43e303a05f012815cef60b611a9c7"
        },
        {
          "url": "https://github.com/python/cpython/commit/d10950739a78f54d0718d88fb5a868374603c084"
        },
        {
          "url": "https://github.com/python/cpython/issues/141707"
        },
        {
          "url": "https://github.com/python/cpython/pull/143934"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/EOMI5I66ZMKQ2INNFT6T7IAIKUGPZYIE/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13462"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13462"
        }
      ],
      "published": "2026-03-12T18:16:21+00:00",
      "updated": "2026-08-13T01:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13837",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13837"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13837"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/568342cfc8f002d9a15f30238f26b9d2e0e79036"
        },
        {
          "url": "https://github.com/python/cpython/commit/5a8b19677d818fb41ee55f310233772e15aa1a2b"
        },
        {
          "url": "https://github.com/python/cpython/commit/694922cf40aa3a28f898b5f5ee08b71b4922df70"
        },
        {
          "url": "https://github.com/python/cpython/commit/71fa8eb8233b37f16c88b6e3e583b461b205d1ba"
        },
        {
          "url": "https://github.com/python/cpython/commit/b64441e4852383645af5b435411a6f849dd1b4cb"
        },
        {
          "url": "https://github.com/python/cpython/commit/cefee7d118a26ef6cd43db59bb9d98ca9a331111"
        },
        {
          "url": "https://github.com/python/cpython/issues/119342"
        },
        {
          "url": "https://github.com/python/cpython/pull/119343"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-13837.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/2X5IBCJXRQAZ5PSERLHMSJFBHFR3QM2C/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13837"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13837"
        }
      ],
      "published": "2025-12-01T18:16:04+00:00",
      "updated": "2026-09-03T03:15:21+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-14017",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        567
      ],
      "description": "When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-14017"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-14017"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14017.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14017.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-jh4h-2cg6-889h"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14017"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14017"
        }
      ],
      "published": "2026-01-08T10:15:45+00:00",
      "updated": "2026-09-15T07:16:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-14524",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        522,
        601
      ],
      "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-14524"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/4"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-14524"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14524.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14524.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-g897-jvjx-78vg"
        },
        {
          "url": "https://hackerone.com/reports/3459417"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14524"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14524"
        }
      ],
      "published": "2026-01-08T10:15:46+00:00",
      "updated": "2026-09-15T07:16:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15079",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        297
      ],
      "description": "When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15079"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/6"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15079"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15079.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15079.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-7q9p-cx8r-rh2q"
        },
        {
          "url": "https://hackerone.com/reports/3477116"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15079"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15079"
        }
      ],
      "published": "2026-01-08T10:15:47+00:00",
      "updated": "2026-09-15T07:16:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15224",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        287
      ],
      "description": "When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15224"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15224"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15224.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15224.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-hccr-q52r-4w88"
        },
        {
          "url": "https://hackerone.com/reports/3480925"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15224"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15224"
        }
      ],
      "published": "2026-01-08T10:15:47+00:00",
      "updated": "2026-09-15T07:16:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15282",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15282"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15282"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/05356b1cc153108aaf27f3b72ce438af4aa218c0"
        },
        {
          "url": "https://github.com/python/cpython/commit/34d76b00dabde81a793bd06dd8ecb057838c4b38"
        },
        {
          "url": "https://github.com/python/cpython/commit/3f396ca9d7bbe2a50ea6b8c9b27c0082884d9f80"
        },
        {
          "url": "https://github.com/python/cpython/commit/4ed11d3cd288e6b90196a15c5a825a45d318fe47"
        },
        {
          "url": "https://github.com/python/cpython/commit/a35ca3be5842505dab74dc0b90b89cde0405017a"
        },
        {
          "url": "https://github.com/python/cpython/commit/f25509e78e8be6ea73c811ac2b8c928c28841b9f"
        },
        {
          "url": "https://github.com/python/cpython/issues/143925"
        },
        {
          "url": "https://github.com/python/cpython/pull/143926"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-15282.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/X66HL7SISGJT33J53OHXMZT4DFLMHVKF/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15282"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15282"
        }
      ],
      "published": "2026-01-20T22:15:50+00:00",
      "updated": "2026-06-17T08:37:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15468",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: If an application using the SSL_CIPHER_find() function in\na QUIC protocol client or server receives an unknown cipher suite from\nthe peer, a NULL dereference occurs.\n\nImpact summary: A NULL pointer dereference leads to abnormal termination of\nthe running process causing Denial of Service.\n\nSome applications call SSL_CIPHER_find() from the client_hello_cb callback\non the cipher ID received from the peer. If this is done with an SSL object\nimplementing the QUIC protocol, NULL pointer dereference will happen if\nthe examined cipher ID is unknown or unsupported.\n\nAs it is not very common to call this function in applications using the QUIC \nprotocol and the worst outcome is Denial of Service, the issue was assessed\nas Low severity.\n\nThe vulnerable code was introduced in the 3.2 version with the addition\nof the QUIC protocol support.\n\nThe FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue,\nas the QUIC implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15468"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15468"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-rhx3-fg8p-f9m4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/1f08e54bad32843044fe8a675948d65e3b4ece65"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7c88376731c589ee5b36116c5a6e32d5ae5f7ae2"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/b2539639400288a4580fe2d76247541b976bade4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d75b309879631d45b972396ce4e5102559c64ac7"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-15468.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15468"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15468"
        }
      ],
      "published": "2026-01-27T16:16:14+00:00",
      "updated": "2026-06-17T08:37:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-15469",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        347
      ],
      "description": "Issue summary: The 'openssl dgst' command-line tool silently truncates input\ndata to 16MB when using one-shot signing algorithms and reports success instead\nof an error.\n\nImpact summary: A user signing or verifying files larger than 16MB with\none-shot algorithms (such as Ed25519, Ed448, or ML-DSA) may believe the entire\nfile is authenticated while trailing data beyond 16MB remains unauthenticated.\n\nWhen the 'openssl dgst' command is used with algorithms that only support\none-shot signing (Ed25519, Ed448, ML-DSA-44, ML-DSA-65, ML-DSA-87), the input\nis buffered with a 16MB limit. If the input exceeds this limit, the tool\nsilently truncates to the first 16MB and continues without signaling an error,\ncontrary to what the documentation states. This creates an integrity gap where\ntrailing bytes can be modified without detection if both signing and\nverification are performed using the same affected codepath.\n\nThe issue affects only the command-line tool behavior. Verifiers that process\nthe full message using library APIs will reject the signature, so the risk\nprimarily affects workflows that both sign and verify with the affected\n'openssl dgst' command. Streaming digest algorithms for 'openssl dgst' and\nlibrary users are unaffected.\n\nThe FIPS modules in 3.5 and 3.6 are not affected by this issue, as the\ncommand-line tools are outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.5 and 3.6 are vulnerable to this issue.\n\nOpenSSL 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15469"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15469"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-v2vr-926q-29fr"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/310f305eb92ea8040d6b3cb75a5feeba8e6acf2f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a7936fa4bd23c906e1955a16a0a0ab39a4953a61"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-15469.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15469"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15469"
        }
      ],
      "published": "2026-01-27T16:16:14+00:00",
      "updated": "2026-06-17T08:37:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-1632",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        404,
        476
      ],
      "description": "A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1632"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1632"
        },
        {
          "url": "https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1632"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7454-1"
        },
        {
          "url": "https://vuldb.com/?ctiid.296619"
        },
        {
          "url": "https://vuldb.com/?id.296619"
        },
        {
          "url": "https://vuldb.com/?submit.496460"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1632"
        }
      ],
      "published": "2025-02-24T14:15:11+00:00",
      "updated": "2026-06-17T08:39:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-1795",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        116
      ],
      "description": "During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the separating comma remains a plan comma. This can result in the address header being misinterpreted by some mail servers.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1795"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1795"
        },
        {
          "url": "https://github.com/python/cpython/commit/09fab93c3d857496c0bd162797fab816c311ee48"
        },
        {
          "url": "https://github.com/python/cpython/commit/70754d21c288535e86070ca7a6e90dcb670b8593"
        },
        {
          "url": "https://github.com/python/cpython/commit/9148b77e0af91cdacaa7fe3dfac09635c3fe9a74"
        },
        {
          "url": "https://github.com/python/cpython/commit/a4ef689ce670684ec132204b1cd03720c8e0a03d"
        },
        {
          "url": "https://github.com/python/cpython/commit/d4df3c55e4c5513947f907f24766b34d2ae8c090"
        },
        {
          "url": "https://github.com/python/cpython/issues/100884"
        },
        {
          "url": "https://github.com/python/cpython/pull/100885"
        },
        {
          "url": "https://github.com/python/cpython/pull/119099"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/MB62IZMEC3UM6SGHP5LET5JX2Y7H4ZUR/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1795"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7570-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1795"
        }
      ],
      "published": "2025-02-28T19:15:36+00:00",
      "updated": "2026-07-31T14:16:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-25724",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        252
      ],
      "description": "list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-25724"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:9431"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-25724"
        },
        {
          "url": "https://bugzilla.redhat.com/2349221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2349221"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-25724"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-9431.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:9431"
        },
        {
          "url": "https://gist.github.com/Ekkosun/a83870ce7f3b7813b9b462a395e8ad92"
        },
        {
          "url": "https://github.com/Ekkosun/pocs/blob/main/bsdtarbug"
        },
        {
          "url": "https://github.com/advisories/GHSA-722w-734r-qg74"
        },
        {
          "url": "https://github.com/libarchive/libarchive/blob/b439d586f53911c84be5e380445a8a259e19114c/tar/util.c#L751-L752"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-25724.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-9431.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25724"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7454-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-25724"
        }
      ],
      "published": "2025-03-02T02:15:36+00:00",
      "updated": "2026-06-17T09:01:02+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-27113",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-27113"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/12"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/13"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/4"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/5"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/8"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-27113"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/861"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27113"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250306-0004/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7302-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-27113"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/02/18/2"
        }
      ],
      "published": "2025-02-18T23:15:10+00:00",
      "updated": "2026-06-17T09:03:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-28164",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        401,
        120
      ],
      "description": "Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-28164"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-28164"
        },
        {
          "url": "https://gist.github.com/kittener/506516f8c22178005b4379c8b2a7de20"
        },
        {
          "url": "https://github.com/pnggroup/libpng/issues/655"
        },
        {
          "url": "https://github.com/pnggroup/libpng/pull/657"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28164"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7993-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-28164"
        }
      ],
      "published": "2026-01-27T16:16:14+00:00",
      "updated": "2026-06-17T09:04:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.6.34-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-30258",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        754
      ],
      "description": "In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-30258"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-30258"
        },
        {
          "url": "https://dev.gnupg.org/T7527"
        },
        {
          "url": "https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30258"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7412-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7412-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-30258"
        }
      ],
      "published": "2025-03-19T20:15:20+00:00",
      "updated": "2026-06-17T09:08:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.2.20-4.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-3360",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-3360"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-3360"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2357754"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3647"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/work_items/3647"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00024.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3360"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-3360"
        }
      ],
      "published": "2025-04-07T13:15:43+00:00",
      "updated": "2026-06-30T15:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-177.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-4516",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "There is an issue in CPython when using `bytes.decode(\"unicode_escape\", error=\"ignore|replace\")`. If you are not using the \"unicode_escape\" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-4516"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/16/4"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/19/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23530"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-4516"
        },
        {
          "url": "https://bugzilla.redhat.com/2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/2321440"
        },
        {
          "url": "https://bugzilla.redhat.com/2325776"
        },
        {
          "url": "https://bugzilla.redhat.com/2343237"
        },
        {
          "url": "https://bugzilla.redhat.com/2366509"
        },
        {
          "url": "https://bugzilla.redhat.com/2370010"
        },
        {
          "url": "https://bugzilla.redhat.com/2370014"
        },
        {
          "url": "https://bugzilla.redhat.com/2370016"
        },
        {
          "url": "https://bugzilla.redhat.com/2372426"
        },
        {
          "url": "https://bugzilla.redhat.com/2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2321440"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2325776"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2343237"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2366509"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370010"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370014"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370016"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2372426"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11168"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5642"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9287"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0938"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4330"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4435"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4516"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4517"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6069"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8291"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2025-23530.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:23530"
        },
        {
          "url": "https://github.com/python/cpython/commit/4398b788ffc1f954a2c552da285477d42a571292"
        },
        {
          "url": "https://github.com/python/cpython/commit/5646648678295a44aa82636c6e92826651baf33a"
        },
        {
          "url": "https://github.com/python/cpython/commit/6279eb8c076d89d3739a6edb393e43c7929b429d"
        },
        {
          "url": "https://github.com/python/cpython/commit/69b4387f78f413e8c47572a85b3478c47eba8142"
        },
        {
          "url": "https://github.com/python/cpython/commit/73b3040f592436385007918887b7e2132aa8431f"
        },
        {
          "url": "https://github.com/python/cpython/commit/8d35fd1b34935221aff23a1ab69a429dd156be77"
        },
        {
          "url": "https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e"
        },
        {
          "url": "https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e%20%28main%29"
        },
        {
          "url": "https://github.com/python/cpython/commit/ab9893c40609935e0d40a6d2a7307ea51aec598b"
        },
        {
          "url": "https://github.com/python/cpython/issues/133767"
        },
        {
          "url": "https://github.com/python/cpython/pull/129648"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-4516.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-23530.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L75IPBBTSCYEF56I2M4KIW353BB3AY74/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4516"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7570-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-4516"
        }
      ],
      "published": "2025-05-15T14:15:31+00:00",
      "updated": "2026-07-31T14:16:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-45582",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        24
      ],
      "description": "GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of \"Member name contains '..'\" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain \"x -> ../../../../../home/victim/.ssh\" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in which \"tar xf\" is run more than once (e.g., when installing a package can automatically install two dependencies that are set up as untrusted tarballs instead of official packages). NOTE: the official GNU Tar manual has an otherwise-empty directory for each \"tar xf\" in its Security Rules of Thumb; however, third-party advice leads users to run \"tar xf\" more than once into the same directory.",
      "recommendation": "Upgrade tar to version 2:1.30-13.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-45582"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/11/01/6"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:0067"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-45582"
        },
        {
          "url": "https://bugzilla.redhat.com/2379592"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2379592"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-45582"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-0067.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:0067"
        },
        {
          "url": "https://github.com/i900008/vulndb/blob/main/Gnu_tar_vuln.md"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-45582.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70390.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-tar/2025-08/msg00012.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45582"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8510-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-45582"
        },
        {
          "url": "https://www.gnu.org/software/tar/"
        },
        {
          "url": "https://www.gnu.org/software/tar/manual/html_node/Integrity.html"
        },
        {
          "url": "https://www.gnu.org/software/tar/manual/html_node/Integrity.html#Integrity"
        },
        {
          "url": "https://www.gnu.org/software/tar/manual/html_node/Security-rules-of-thumb.html"
        }
      ],
      "published": "2025-07-11T17:15:37+00:00",
      "updated": "2026-06-17T09:25:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-4598",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        364
      ],
      "description": "A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.\n\nA SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-4598"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Jun/9"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/06/05/1"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/06/05/3"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/08/18/3"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:22660"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:22868"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23227"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23234"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:0414"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1652"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18153"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-4598"
        },
        {
          "url": "https://blogs.oracle.com/linux/post/analysis-of-cve-2025-4598"
        },
        {
          "url": "https://bugzilla.redhat.com/2369242"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369242"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://ciq.com/blog/the-real-danger-of-systemd-coredump-cve-2025-4598/"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4598"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-22660.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:22660"
        },
        {
          "url": "https://git.kernel.org/linus/b5325b2a270fcaf7b2a9a0f23d422ca8a5a8bdea"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/0c49e0049b7665bb7769a13ef346fef92e1ad4d6%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/13902e025321242b1d95c6d8b4e482b37f58cdef%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/49f1f2d4a7612bbed5211a73d11d6a94fbe3bb69%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/76e0ab49c47965877c19772a2b3bf55f6417ca39%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/868d95577ec9f862580ad365726515459be582fc%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/8fc7b2a211eb13ef1a94250b28e1c79cab8bdcb9%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/9ce8e3e449def92c75ada41b7d10c5bc3946be77%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/e6a8687b939ab21854f12f59a3cce703e32768cf%20%28main%29"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-4598.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18153.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/07/msg00022.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4598"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7559-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-4598"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/05/29/3"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/08/18/3"
        },
        {
          "url": "https://www.qualys.com/2025/05/29/apport-coredump/apport-coredump.txt"
        }
      ],
      "published": "2025-05-30T14:15:23+00:00",
      "updated": "2026-09-01T12:17:22+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.19",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.19",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.19",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-47268",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "ping in iputils before 20250602 allows a denial of service (application error or incorrect data collection) via a crafted ICMP Echo Reply packet, because of a signed 64-bit integer overflow in timestamp multiplication.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-47268"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:9432"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-47268"
        },
        {
          "url": "https://bugzilla.redhat.com/2364090"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2364090"
        },
        {
          "url": "https://bugzilla.suse.com/show_bug.cgi?id=1242300"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47268"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-9432.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:9432"
        },
        {
          "url": "https://github.com/Zephkek/ping-rtt-overflow/"
        },
        {
          "url": "https://github.com/iputils/iputils/commit/070cfacd7348386173231fb16fad4983d4e6ae40"
        },
        {
          "url": "https://github.com/iputils/iputils/issues/584"
        },
        {
          "url": "https://github.com/iputils/iputils/pull/585"
        },
        {
          "url": "https://github.com/iputils/iputils/releases/tag/20250602"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-47268.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-9432.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47268"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7670-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-47268"
        }
      ],
      "published": "2025-05-05T14:15:29+00:00",
      "updated": "2026-06-17T09:27:38+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "20180629-11.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-47273",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        22
      ],
      "description": "setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.",
      "recommendation": "Upgrade setuptools to version 78.1.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-47273"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:10407"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:13578"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-47273"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2025-47273"
        },
        {
          "url": "https://bugzilla.redhat.com/2366982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2366982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47273"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-13578.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:10407"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2025-49.yaml"
        },
        {
          "url": "https://github.com/pypa/setuptools"
        },
        {
          "url": "https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88"
        },
        {
          "url": "https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b"
        },
        {
          "url": "https://github.com/pypa/setuptools/issues/4946"
        },
        {
          "url": "https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-47273.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-9940.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47273"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7544-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8010-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-47273"
        }
      ],
      "published": "2025-05-17T16:15:19+00:00",
      "updated": "2026-06-17T09:27:38+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@70.3.0",
          "versions": [
            {
              "version": "70.3.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:pypi/setuptools@70.3.0"
        }
      ]
    },
    {
      "id": "CVE-2025-4878",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.6,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-4878"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-4878"
        },
        {
          "url": "https://bugzilla.redhat.com/2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-18683.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://git.libssh.org/projects/libssh.git/commit/?id=697650caa97eaf7623924c75f9fcfec6dd423cd1"
        },
        {
          "url": "https://git.libssh.org/projects/libssh.git/commit/?id=b35ee876adc92a208d47194772e99f9c71e0bedb"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-4878.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4878"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7619-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7696-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-4878"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2025-4878.txt"
        }
      ],
      "published": "2025-07-22T15:15:36+00:00",
      "updated": "2026-09-01T13:17:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-48964",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "ping in iputils before 20250602 allows a denial of service (application error in adaptive ping mode or incorrect data collection) via a crafted ICMP Echo Reply packet, because a zero timestamp can lead to large intermediate values that have an integer overflow when squared during statistics calculations. NOTE: this issue exists because of an incomplete fix for CVE-2025-47268 (that fix was only about timestamp calculations, and it did not account for a specific scenario where the original timestamp in the ICMP payload is zero).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-48964"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:17558"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-48964"
        },
        {
          "url": "https://bugzilla.redhat.com/2382657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2382657"
        },
        {
          "url": "https://bugzilla.suse.com/show_bug.cgi?id=1243772"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-48964"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-17558.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:17558"
        },
        {
          "url": "https://github.com/iputils/iputils/commit/afa36390394a6e0cceba03b52b59b6d41710608c"
        },
        {
          "url": "https://github.com/iputils/iputils/issues"
        },
        {
          "url": "https://github.com/iputils/iputils/releases/tag/20250602"
        },
        {
          "url": "https://github.com/iputils/iputils/security/advisories/GHSA-25fr-jw29-74f9"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-48964.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18162.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48964"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7670-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-48964"
        }
      ],
      "published": "2025-07-22T18:15:36+00:00",
      "updated": "2026-06-17T09:30:35+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "20180629-11.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-50181",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        601
      ],
      "description": "urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-50181"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-50181"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2025-50181"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.5.0"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-50181"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7599-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7599-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-50181"
        }
      ],
      "published": "2025-06-19T01:15:24+00:00",
      "updated": "2026-06-17T09:34:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-50182",
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        601
      ],
      "description": "urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpRequest. This means Python libraries can be used to make HTTP requests from a browser or Node.js. Additionally, urllib3 provides a mechanism to control redirects, but the retries and redirect parameters are ignored with Pyodide; the runtime itself determines redirect behavior. This issue has been patched in version 2.5.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-50182"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-50182"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2025-50182"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.5.0"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-50182"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7599-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-50182"
        }
      ],
      "published": "2025-06-19T02:15:17+00:00",
      "updated": "2026-06-17T09:34:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5278",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        121
      ],
      "description": "A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.",
      "recommendation": "Upgrade coreutils-single to version 8.30-21.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5278"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/27/2"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/29/1"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/29/2"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28911"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33124"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33313"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33612"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34102"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44481"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46836"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50205"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69964"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72502"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5278"
        },
        {
          "url": "https://bugzilla.redhat.com/2368764"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2368764"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/coreutils.git/tree/NEWS?id=8c9602e3a145e9596dc1a63c6ed67865814b6633#n14"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5278"
        },
        {
          "url": "https://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-28911.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28911"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-5278.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69964.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-coreutils/2025-05/msg00036.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-coreutils/2025-05/msg00040.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5278"
        },
        {
          "url": "https://security-tracker.debian.org/tracker/CVE-2025-5278"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8697-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5278"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/05/27/2"
        }
      ],
      "published": "2025-05-27T21:15:23+00:00",
      "updated": "2026-09-29T01:16:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.30-20.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-5351",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        415
      ],
      "description": "A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5351"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5351"
        },
        {
          "url": "https://bugzilla.redhat.com/2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-18683.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-5351.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5351"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7619-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5351"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2025-5351.txt"
        }
      ],
      "published": "2025-07-04T09:15:37+00:00",
      "updated": "2026-09-01T12:17:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-5915",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.6,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5915"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5915"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370865"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2599"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5915"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5915"
        }
      ],
      "published": "2025-06-09T20:15:26+00:00",
      "updated": "2026-09-01T13:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5916",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5916"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5916"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370872"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2568"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2568/commits/bce70c4c26864df2a8d6953e7db6e4b156253508"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5916"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5916"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-09-01T13:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5917",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5917"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5917"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370874"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2588"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5917"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5917"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-09-01T13:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5918",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5918"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5918"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370877"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2584"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5918"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5918"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-09-01T13:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-6069",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1333
      ],
      "description": "The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-6069"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23342"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-6069"
        },
        {
          "url": "https://bugzilla.redhat.com/2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5642"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6069"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8291"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-23342.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:23342"
        },
        {
          "url": "https://github.com/python/cpython/commit/4455cbabf991e202185a25a631af206f60bbc949"
        },
        {
          "url": "https://github.com/python/cpython/commit/6eb6c5dbfb528bd07d77b60fd71fd05d81d45c41"
        },
        {
          "url": "https://github.com/python/cpython/commit/6eb6c5dbfb528bd07d77b60fd71fd05d81d45c41%20%28main%29"
        },
        {
          "url": "https://github.com/python/cpython/commit/8d1b3dfa09135affbbf27fb8babcf3c11415df49"
        },
        {
          "url": "https://github.com/python/cpython/commit/ab0893fd5c579d9cea30841680e6d35fc478afb5"
        },
        {
          "url": "https://github.com/python/cpython/commit/d851f8e258c7328814943e923a7df81bca15df4b"
        },
        {
          "url": "https://github.com/python/cpython/commit/f3c6f882cddc8dc30320d2e73edf019e201394fc"
        },
        {
          "url": "https://github.com/python/cpython/commit/fdc9d214c01cb4588f540cfa03726bbf2a33fc15"
        },
        {
          "url": "https://github.com/python/cpython/issues/135462"
        },
        {
          "url": "https://github.com/python/cpython/pull/135464"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-6069.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-23530.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/K5PIYLR6EP3WR7ZOKKYQUWEDNQVUXOYM/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-6069"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7710-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-6069"
        }
      ],
      "published": "2025-06-17T14:15:33+00:00",
      "updated": "2026-07-31T14:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-6075",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "If the value passed to os.path.expandvars() is user-controlled a \nperformance degradation is possible when expanding environment \nvariables.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-6075"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-6075"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5642"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6069"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8291"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:23342"
        },
        {
          "url": "https://github.com/python/cpython/commit/2e6150adccaaf5bd95d4c19dfd04a36e0b325d8c"
        },
        {
          "url": "https://github.com/python/cpython/commit/5dceb93486176e6b4a6d9754491005113eb23427"
        },
        {
          "url": "https://github.com/python/cpython/commit/631ba3407e3348ccd56ce5160c4fb2c5dc5f4d84"
        },
        {
          "url": "https://github.com/python/cpython/commit/892747b4cf0f95ba8beb51c0d0658bfaa381ebca"
        },
        {
          "url": "https://github.com/python/cpython/commit/9ab89c026aa9611c4b0b67c288b8303a480fe742"
        },
        {
          "url": "https://github.com/python/cpython/commit/c8a5f3435c342964e0a432cc9fb448b7dbecd1ba"
        },
        {
          "url": "https://github.com/python/cpython/commit/f029e8db626ddc6e3a3beea4eff511a71aaceb5c"
        },
        {
          "url": "https://github.com/python/cpython/issues/136065"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-6075.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/IUP5QJ6D4KK6ULHOMPC7DPNKRYQTQNLA/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-6075"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7886-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7886-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8614-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-6075"
        }
      ],
      "published": "2025-10-31T17:15:48+00:00",
      "updated": "2026-10-07T21:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-60753",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        400,
        835
      ],
      "description": "An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-60753"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-60753"
        },
        {
          "url": "https://github.com/Papya-j/CVE/tree/main/CVE-2025-60753"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/2725"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-60753"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-60753"
        }
      ],
      "published": "2025-11-05T16:15:40+00:00",
      "updated": "2026-06-17T09:50:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-64118",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        362,
        367
      ],
      "description": "node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if tar file was changed on disk to a smaller size while being read. This vulnerability is fixed in 7.5.2.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-64118"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-64118"
        },
        {
          "url": "https://github.com/isaacs/node-tar"
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/5330eb04bc43014f216e5c271b40d5c00d45224d"
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/5e1a8e638600d3c3a2969b4de6a6ec44fa8d74c9"
        },
        {
          "url": "https://github.com/isaacs/node-tar/issues/445"
        },
        {
          "url": "https://github.com/isaacs/node-tar/pull/446"
        },
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-29xp-372q-xqph"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64118"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64118"
        }
      ],
      "published": "2025-10-30T18:15:33+00:00",
      "updated": "2026-10-07T22:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-64505",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access. This issue has been patched in version 1.6.51.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-64505"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-64505"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/6a528eb5fd0dd7f6de1c39d30de0e41473431c37"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/6a528eb5fd0dd7f6de1c39d30de0e41473431c37%20%28v1.6.51%29"
        },
        {
          "url": "https://github.com/pnggroup/libpng/pull/748"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-4952-h5wq-4m42"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64505"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7924-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8081-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64505"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/11/22/1"
        }
      ],
      "published": "2025-11-25T00:15:47+00:00",
      "updated": "2026-06-17T09:54:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.6.34-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-64506",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_write_image_8bit function when processing 8-bit images through the simplified write API with convert_to_8bit enabled. The vulnerability affects 8-bit grayscale+alpha, RGB/RGBA, and images with incomplete row data. A conditional guard incorrectly allows 8-bit input to enter code expecting 16-bit input, causing reads up to 2 bytes beyond allocated buffer boundaries. This issue has been patched in version 1.6.51.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-64506"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-64506"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/2bd84c019c300b78e811743fbcddb67c9d9bf821"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/2bd84c019c300b78e811743fbcddb67c9d9bf821%20%28v1.6.51%29"
        },
        {
          "url": "https://github.com/pnggroup/libpng/pull/749"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-qpr4-xm66-hww6"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64506"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7924-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64506"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/11/22/1"
        }
      ],
      "published": "2025-11-25T00:15:47+00:00",
      "updated": "2026-06-17T09:54:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.6.34-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-66382",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        407
      ],
      "description": "In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-66382"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/12/02/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-66382"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/issues/1076"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-66382"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-66382"
        }
      ],
      "published": "2025-11-28T07:15:57+00:00",
      "updated": "2026-06-17T09:56:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-68160",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: Writing large, newline-free data into a BIO chain using the\nline-buffering filter where the next BIO performs short writes can trigger\na heap-based out-of-bounds write.\n\nImpact summary: This out-of-bounds write can cause memory corruption which\ntypically results in a crash, leading to Denial of Service for an application.\n\nThe line-buffering BIO filter (BIO_f_linebuffer) is not used by default in\nTLS/SSL data paths. In OpenSSL command-line applications, it is typically\nonly pushed onto stdout/stderr on VMS systems. Third-party applications that\nexplicitly use this filter with a BIO chain that can short-write and that\nwrite large, newline-free data influenced by an attacker would be affected.\nHowever, the circumstances where this could happen are unlikely to be under\nattacker control, and BIO_f_linebuffer is unlikely to be handling non-curated\ndata controlled by an attacker. For that reason the issue was assessed as\nLow severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the BIO implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-68160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-68160"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-g78j-46j5-97cr"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/384011202af92605d926fafe4a0bcd6b65d162ad"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/475c466ef2fbd8fc1df6fae1c3eed9c813fc8ff6"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4c96fbba618e1940f038012506ee9e21d32ee12c"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/6845c3b6460a98b1ec4e463baa2ea1a63a32d7c0"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/68a7cd2e2816c3a02f4d45a2ce43fc04fac97096"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-68160.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68160"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68160"
        }
      ],
      "published": "2026-01-27T16:16:15+00:00",
      "updated": "2026-06-17T09:58:39+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-68972",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        347
      ],
      "description": "In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-68972"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-68972"
        },
        {
          "url": "https://github.com/advisories/GHSA-w789-3q45-984r"
        },
        {
          "url": "https://gpg.fail/formfeed"
        },
        {
          "url": "https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i"
        },
        {
          "url": "https://news.ycombinator.com/item?id=46404339"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68972"
        }
      ],
      "published": "2025-12-27T23:15:40+00:00",
      "updated": "2026-06-17T09:59:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.2.20-4.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-69418",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        325
      ],
      "description": "Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. The authentication checksum<br>also excludes the true tail bytes.<br><br>However, typical OpenSSL consumers using EVP are not affected because the<br>higher-level EVP and provider OCB implementations split inputs so that full<br>blocks and trailing partial blocks are processed in separate calls, avoiding<br>the problematic code path. Additionally, TLS does not use OCB ciphersuites.<br>The vulnerability only affects applications that call the low-level<br>CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with<br>non-block-aligned lengths in a single call on hardware-accelerated builds.<br>For these reasons the issue was assessed as Low severity.<br><br>The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected<br>by this issue, as OCB mode is not a FIPS-approved algorithm.<br><br>OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.<br><br>OpenSSL 1.0.2 is not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-69418"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-69418"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-78qr-24v5-7q73"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/372fc5c77529695b05b4f5b5187691a57ef5dffc"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4016975d4469cd6b94927c607f7c511385f928d8"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/52d23c86a54adab5ee9f80e48b242b52c4cc2347"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a7589230356d908c0eca4b969ec4f62106f4f5ae"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ed40856d7d4ba6cb42779b6770666a65f19cb977"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-69418.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-69418"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-69418"
        }
      ],
      "published": "2026-01-27T16:16:33+00:00",
      "updated": "2026-06-17T10:00:39+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-69420",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        754
      ],
      "description": "Issue summary: A type confusion vulnerability exists in the TimeStamp Response\nverification code where an ASN1_TYPE union member is accessed without first\nvalidating the type, causing an invalid or NULL pointer dereference when\nprocessing a malformed TimeStamp Response file.\n\nImpact summary: An application calling TS_RESP_verify_response() with a\nmalformed TimeStamp Response can be caused to dereference an invalid or\nNULL pointer when reading, resulting in a Denial of Service.\n\nThe functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2()\naccess the signing cert attribute value without validating its type.\nWhen the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory\nthrough the ASN1_TYPE union, causing a crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nTimeStamp Response to an application that verifies timestamp responses. The\nTimeStamp protocol (RFC 3161) is not widely used and the impact of the\nexploit is just a Denial of Service. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the TimeStamp Response implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-69420"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-69420"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-w42r-ph9f-9x66"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/27c7012c91cc986a598d7540f3079dfde2416eb9"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4e254b48ad93cc092be3dd62d97015f33f73133a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/564fd9c73787f25693bf9e75faf7bf6bb1305d4e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5eb0770ffcf11b785cf374ff3c19196245e54f1b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a99349ebfc519999edc50620abe24d599b9eb085"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-69420.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-69420"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-69420"
        }
      ],
      "published": "2026-01-27T16:16:34+00:00",
      "updated": "2026-06-17T10:00:40+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-69421",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer\ndereference in the PKCS12_item_decrypt_d2i_ex() function.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to\nDenial of Service for an application processing PKCS#12 files.\n\nThe PKCS12_item_decrypt_d2i_ex() function does not check whether the oct\nparameter is NULL before dereferencing it. When called from\nPKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can\nbe NULL, causing a crash. The vulnerability is limited to Denial of Service\nand cannot be escalated to achieve code execution or memory disclosure.\n\nExploiting this issue requires an attacker to provide a malformed PKCS#12 file\nto an application that processes it. For that reason the issue was assessed as\nLow severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-69421"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-69421"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-w9rv-xc8m-cmqp"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3524a29271f8191b8fd8a5257eb05173982a097b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/36ecb4960872a4ce04bf6f1e1f4e78d75ec0c0c7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4bbc8d41a72c842ce4077a8a3eccd1109aaf74bd"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/643986985cd1c21221f941129d76fe0c2785aeb3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a2dbc539f0f9cc63832709fa5aa33ad9495eb19c"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-69421.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-69421"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-69421"
        }
      ],
      "published": "2026-01-27T16:16:34+00:00",
      "updated": "2026-06-17T10:00:40+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-7039",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        22
      ],
      "description": "A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-7039"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-7039"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2392423"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3716"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-7039"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-7039"
        }
      ],
      "published": "2025-09-03T02:15:38+00:00",
      "updated": "2026-06-17T10:04:08+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-177.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-70873",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        244
      ],
      "description": "An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-70873"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-70873"
        },
        {
          "url": "https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-70873"
        },
        {
          "url": "https://sqlite.org/forum/forumpost/761eac3c82"
        },
        {
          "url": "https://sqlite.org/src/info/3d459f1fb1bd1b5e"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-70873"
        }
      ],
      "published": "2026-03-12T19:16:15+00:00",
      "updated": "2026-06-17T10:03:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.26.0-21.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-8114",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL pointer dereference. This issue can cause the client or server to crash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-8114"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-8114"
        },
        {
          "url": "https://bugzilla.redhat.com/2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-18683.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://git.libssh.org/projects/libssh.git/commit/?id=53ac23ded4cb2c5463f6c4cd1525331bd578812d"
        },
        {
          "url": "https://git.libssh.org/projects/libssh.git/commit/?id=65f363c9"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-8114.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-8114"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7849-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-8114"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2025-8114.txt"
        }
      ],
      "published": "2025-07-24T15:15:27+00:00",
      "updated": "2026-09-01T12:17:32+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-8277",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        401
      ],
      "description": "A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory. This issue can lead to crashes on the client side, particularly when using libgcrypt, which impacts application stability and availability.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-8277"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-8277"
        },
        {
          "url": "https://bugzilla.redhat.com/2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-18683.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-8277.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-8277"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-8277"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2025-8277.txt"
        }
      ],
      "published": "2025-09-09T12:15:30+00:00",
      "updated": "2026-09-01T13:18:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-8291",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1285
      ],
      "description": "The 'zipfile' module would not check the validity of the ZIP64 End of\nCentral Directory (EOCD) Locator record offset value would not be used to\nlocate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be\nassumed to be the previous record in the ZIP archive. This could be abused\nto create ZIP archives that are handled differently by the 'zipfile' module\ncompared to other ZIP implementations.\n\n\nRemediation maintains this behavior, but checks that the offset specified\nin the ZIP64 EOCD Locator record matches the expected value.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-8291"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23342"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-8291"
        },
        {
          "url": "https://bugzilla.redhat.com/2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5642"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6069"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8291"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-23342.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:23342"
        },
        {
          "url": "https://github.com/google/security-research/security/advisories/GHSA-hhv7-p4pg-wm6p"
        },
        {
          "url": "https://github.com/psf/advisory-database/blob/main/advisories/python/PSF-2025-12.json"
        },
        {
          "url": "https://github.com/python/cpython/commit/162997bb70e067668c039700141770687bc8f267"
        },
        {
          "url": "https://github.com/python/cpython/commit/1d29afb0d6218aa8fb5e1e4a6133a4778d89bb46"
        },
        {
          "url": "https://github.com/python/cpython/commit/333d4a6f4967d3ace91492a39ededbcf3faa76a6"
        },
        {
          "url": "https://github.com/python/cpython/commit/76437ac248ad8ca44e9bf697b02b1e2241df2196"
        },
        {
          "url": "https://github.com/python/cpython/commit/8392b2f0d35678407d9ce7d95655a5b77de161b4"
        },
        {
          "url": "https://github.com/python/cpython/commit/bca11ae7d575d87ed93f5dd6a313be6246e3e388"
        },
        {
          "url": "https://github.com/python/cpython/commit/d11e69d6203080e3ec450446bfed0516727b85c3"
        },
        {
          "url": "https://github.com/python/cpython/issues/139700"
        },
        {
          "url": "https://github.com/python/cpython/pull/139702"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-8291.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-0123.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/QECOPWMTH4VPPJAXAH2BGTA4XADOP62G/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-8291"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7886-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7886-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-8291"
        }
      ],
      "published": "2025-10-07T18:16:00+00:00",
      "updated": "2026-10-08T22:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0672",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0672"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0672"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/62700107418eb2cca3fc88da036a243ea975f172"
        },
        {
          "url": "https://github.com/python/cpython/commit/712452e6f1d4b9f7f8c4c92ebfcaac1705faa440"
        },
        {
          "url": "https://github.com/python/cpython/commit/7852d72b653fea0199acf5fc2a84f6f8b84eba8d"
        },
        {
          "url": "https://github.com/python/cpython/commit/918387e4912d12ffc166c8f2a38df92b6ec756ca"
        },
        {
          "url": "https://github.com/python/cpython/commit/95746b3a13a985787ef53b977129041971ed7f70"
        },
        {
          "url": "https://github.com/python/cpython/commit/b1869ff648bbee0717221d09e6deff46617f3e85"
        },
        {
          "url": "https://github.com/python/cpython/issues/143919"
        },
        {
          "url": "https://github.com/python/cpython/pull/143920"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0672.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/6VFLQQEIX673KXKFUZXCUNE5AZOGZ45M/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0672"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-3"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0672"
        }
      ],
      "published": "2026-01-20T22:15:52+00:00",
      "updated": "2026-06-17T10:11:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0799",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125,
        129,
        787
      ],
      "description": "In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value.  In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.",
      "recommendation": "Upgrade libpcap to version 14:1.9.1-6.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0799"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74441"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0799"
        },
        {
          "url": "https://bugzilla.redhat.com/2529093"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529093"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0799"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-74441.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:74441"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0799.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-76045.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0799"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8824-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0799"
        }
      ],
      "published": "2026-09-05T19:16:55+00:00",
      "updated": "2026-09-08T19:20:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14",
          "versions": [
            {
              "version": "14:1.9.1-5.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-0864",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        74
      ],
      "description": "When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0864"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0864"
        },
        {
          "url": "https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528"
        },
        {
          "url": "https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908"
        },
        {
          "url": "https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f"
        },
        {
          "url": "https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98"
        },
        {
          "url": "https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8"
        },
        {
          "url": "https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6"
        },
        {
          "url": "https://github.com/python/cpython/issues/143927"
        },
        {
          "url": "https://github.com/python/cpython/pull/151559"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0864"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0864"
        }
      ],
      "published": "2026-06-23T18:17:41+00:00",
      "updated": "2026-08-18T17:52:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0964",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        22
      ],
      "description": "A malicious SCP server can send unexpected paths that could make the\nclient application override local files outside of working directory.\nThis could be misused to create malicious executable or configuration\nfiles and make the user execute them under specific consequences.\n\nThis is the same issue as in OpenSSH, tracked as CVE-2019-6111.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0964"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0964"
        },
        {
          "url": "https://bugzilla.redhat.com/2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-18683.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0964.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0964"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0964"
        },
        {
          "url": "https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2026-0964.txt"
        }
      ],
      "published": "2026-03-26T21:17:00+00:00",
      "updated": "2026-09-01T12:17:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0965",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        73
      ],
      "description": "A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by causing the system to try and access dangerous files, such as block devices or large system files, which can disrupt normal operations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0965"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0965"
        },
        {
          "url": "https://bugzilla.redhat.com/2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-18683.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0965.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0965"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0965"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2026-0965.txt"
        }
      ],
      "published": "2026-03-26T21:17:00+00:00",
      "updated": "2026-09-01T13:18:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0966",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        124
      ],
      "description": "A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0966"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7067"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0966"
        },
        {
          "url": "https://bugzilla.redhat.com/2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-18683.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0966.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0966"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0966"
        },
        {
          "url": "https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2026-0966.txt"
        }
      ],
      "published": "2026-03-26T21:17:00+00:00",
      "updated": "2026-09-01T12:17:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0967",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.2,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1333
      ],
      "description": "A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0967"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0967"
        },
        {
          "url": "https://bugzilla.redhat.com/2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-18683.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0967.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0967"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0967"
        },
        {
          "url": "https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2026-0967.txt"
        }
      ],
      "published": "2026-03-26T21:17:00+00:00",
      "updated": "2026-09-01T13:18:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0968",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0968"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0968"
        },
        {
          "url": "https://bugzilla.redhat.com/2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-18683.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0968.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0968"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0968"
        },
        {
          "url": "https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2026-0968.txt"
        }
      ],
      "published": "2026-03-26T21:17:01+00:00",
      "updated": "2026-09-01T13:18:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0988",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0988"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7461"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0988"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429886"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3851"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0988"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7971-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0988"
        }
      ],
      "published": "2026-01-21T12:15:55+00:00",
      "updated": "2026-06-17T10:11:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-177.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0989",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0989"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429933"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/998"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/374"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0989"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0989"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-09-01T13:18:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0990",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0990"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429959"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0990"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0990"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-09-01T12:17:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0992",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0992"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429975"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1019"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0992"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0992"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-09-01T13:18:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-102010",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "cwes": [
        825
      ],
      "description": "A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-102010"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73642"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74569"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-102010"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2478395"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-102010"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-102010"
        }
      ],
      "published": "2026-09-28T19:16:48+00:00",
      "updated": "2026-10-02T03:16:38+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-102633",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-102633"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-102633"
        },
        {
          "url": "https://github.com/libexpat/libexpat"
        },
        {
          "url": "https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/lib/xmlparse.c#L1003"
        },
        {
          "url": "https://github.com/libexpat/libexpat/commit/209801d7fbaf07ab74bae8cb32dd2ab9e5846118"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1392"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-102633"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-102633"
        },
        {
          "url": "https://www.vulncheck.com/advisories/libexpat-2.7.2-through-2.8.5-integer-overflow-in-expat-realloc"
        }
      ],
      "published": "2026-09-29T17:17:06+00:00",
      "updated": "2026-09-29T21:32:59+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-103111",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.6,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L"
        }
      ],
      "cwes": [
        787
      ],
      "description": "PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-103111"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-103111"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-103111"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-103111"
        }
      ],
      "published": "2026-09-30T05:16:45+00:00",
      "updated": "2026-10-04T00:16:35+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "10.32-3.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-103242",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content \u2014 of attacker-chosen length \u2014 past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-103242"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-103242"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2543866"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-103242"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-103242"
        }
      ],
      "published": "2026-09-30T12:17:12+00:00",
      "updated": "2026-09-30T17:16:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-105712",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.6,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L"
        }
      ],
      "cwes": [
        61
      ],
      "description": "gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-105712"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-105712"
        },
        {
          "url": "https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-105712"
        },
        {
          "url": "https://static.dev.gnupg.org/T8159.html"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-105712"
        }
      ],
      "published": "2026-10-05T19:17:19+00:00",
      "updated": "2026-10-06T16:00:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.2.20-4.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-107161",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107161"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-107161"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460420"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107161"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-107161"
        }
      ],
      "published": "2026-10-07T20:17:10+00:00",
      "updated": "2026-10-09T02:17:02+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.1.27-6.el8_5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-107708",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        476
      ],
      "description": "MIT krb5 through 1.22.2 contains a NULL pointer dereference vulnerability in the KDC's get_pac_princ_with_realm() that returns success while leaving the client principal NULL on malformed names. A malicious or compromised cross-realm trusted KDC can send an S4U2Proxy request with a PAC carrying a malformed client name to crash krb5kdc and deny authentication.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107708"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-107708"
        },
        {
          "url": "https://github.com/krb5/krb5"
        },
        {
          "url": "https://github.com/krb5/krb5/blob/krb5-1.22.2-final/src/kdc/kdc_util.c#L639-L676"
        },
        {
          "url": "https://github.com/krb5/krb5/commit/a88a18cafa1040a0c4f9c8d08288fc98831ec86d"
        },
        {
          "url": "https://github.com/krb5/krb5/commit/f6e2c397ceda6467ebbaab8ed66d4895c9f1d6a7"
        },
        {
          "url": "https://github.com/krb5/krb5/pull/1510"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107708"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-107708"
        },
        {
          "url": "https://www.vulncheck.com/advisories/mit-krb5-through-1.22.2-kdc-null-pointer-dereference-via-s4u2proxy-pac"
        }
      ],
      "published": "2026-10-08T21:17:52+00:00",
      "updated": "2026-10-08T21:33:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18.2-34.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18.2-34.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18.2-34.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ]
    },
    {
      "id": "CVE-2026-107778",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        476
      ],
      "description": "MIT Kerberos 5 (krb5) through 1.22.2 contains a NULL pointer dereference in make_cred_list() in rd_cred.c that allows authenticated Kerberos clients to crash services by sending mismatched KRB-CRED arrays. Attackers can send forwarded credentials with more tickets than ticket_info entries through gss_accept_sec_context() to crash GSS-API acceptor services, causing denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107778"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-107778"
        },
        {
          "url": "https://github.com/krb5/krb5"
        },
        {
          "url": "https://github.com/krb5/krb5/blob/krb5-1.22.2-final/src/lib/krb5/krb/rd_cred.c#L77-L112"
        },
        {
          "url": "https://github.com/krb5/krb5/commit/48afa9abb89ab2176bb20624d87d010b9984fc08"
        },
        {
          "url": "https://github.com/krb5/krb5/commit/62196e2b269159a5465f5b8d0ed7cf6f29c3282a"
        },
        {
          "url": "https://github.com/krb5/krb5/pull/1511"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107778"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-107778"
        },
        {
          "url": "https://www.vulncheck.com/advisories/mit-krb5-through-1.22.2-null-pointer-dereference-via-krb5-rd-cred"
        }
      ],
      "published": "2026-10-08T21:17:52+00:00",
      "updated": "2026-10-08T21:33:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18.2-34.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18.2-34.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18.2-34.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ]
    },
    {
      "id": "CVE-2026-11850",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        191
      ],
      "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11850"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25520"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11850"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459970"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11850"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8585-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11850"
        }
      ],
      "published": "2026-06-11T10:16:21+00:00",
      "updated": "2026-08-31T18:17:12+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18.2-34.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18.2-34.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18.2-34.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11856",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        294
      ],
      "description": "Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11856"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69125"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11856"
        },
        {
          "url": "https://bugzilla.redhat.com/2496759"
        },
        {
          "url": "https://bugzilla.redhat.com/2496760"
        },
        {
          "url": "https://bugzilla.redhat.com/2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/2496765"
        },
        {
          "url": "https://bugzilla.redhat.com/2496767"
        },
        {
          "url": "https://bugzilla.redhat.com/2496771"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496759"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496760"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496765"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496767"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496771"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-11856.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11856.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11856.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11856"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8458"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8924"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8926"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8932"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9079"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-69125.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69125"
        },
        {
          "url": "https://github.com/advisories/GHSA-9crq-qh8v-6xmm"
        },
        {
          "url": "https://hackerone.com/reports/3793260"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-11856.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69125.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11856"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8651-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11856"
        }
      ],
      "published": "2026-07-03T07:16:23+00:00",
      "updated": "2026-09-15T07:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11972",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        252,
        606,
        770
      ],
      "description": "When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11972"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11972"
        },
        {
          "url": "https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9"
        },
        {
          "url": "https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365"
        },
        {
          "url": "https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21"
        },
        {
          "url": "https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec"
        },
        {
          "url": "https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192"
        },
        {
          "url": "https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896"
        },
        {
          "url": "https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438"
        },
        {
          "url": "https://github.com/python/cpython/issues/151981"
        },
        {
          "url": "https://github.com/python/cpython/pull/151982"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11972"
        }
      ],
      "published": "2026-06-23T23:16:49+00:00",
      "updated": "2026-08-13T01:16:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-12345",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "cwes": [
        59
      ],
      "description": "The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-12345"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/09/29/40"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-12345"
        },
        {
          "url": "https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970"
        },
        {
          "url": "https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420"
        },
        {
          "url": "https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d"
        },
        {
          "url": "https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993"
        },
        {
          "url": "https://github.com/python/cpython/issues/157579"
        },
        {
          "url": "https://github.com/python/cpython/pull/157580"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12345"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12345"
        }
      ],
      "published": "2026-09-29T18:17:14+00:00",
      "updated": "2026-10-03T01:17:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-12610",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        825
      ],
      "description": "A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-12610"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-12610"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490288"
        },
        {
          "url": "https://github.com/SSSD/sssd/issues/8796"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12610"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8672-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12610"
        }
      ],
      "published": "2026-06-30T10:16:34+00:00",
      "updated": "2026-08-31T19:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.3.1-40.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/pam@1.3.1-40.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-13346",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L"
        }
      ],
      "cwes": [
        36
      ],
      "description": "pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13346"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/29/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13346"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-13346"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2026-3721.yaml"
        },
        {
          "url": "https://github.com/pypa/pip"
        },
        {
          "url": "https://github.com/pypa/pip/commit/10dfb6b9005484578b386f64b9f36982e3dc6679"
        },
        {
          "url": "https://github.com/pypa/pip/pull/14110"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13346"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13346"
        }
      ],
      "published": "2026-07-29T19:16:44+00:00",
      "updated": "2026-08-20T13:17:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-13595",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13595"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26573"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13595"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494101"
        },
        {
          "url": "https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13595"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8702-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13595"
        }
      ],
      "published": "2026-06-29T09:16:28+00:00",
      "updated": "2026-08-31T18:17:13+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-13757",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37469"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49667"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49668"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53371"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54760"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72394"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72399"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72502"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13757"
        },
        {
          "url": "https://bugzilla.redhat.com/2494556"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494556"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-13757"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-49667.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:49667"
        },
        {
          "url": "https://github.com/advisories/GHSA-p2wm-69qx-x25w"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-13757.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-49668.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13757"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8687-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13757"
        }
      ],
      "published": "2026-06-29T19:16:40+00:00",
      "updated": "2026-09-29T01:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.23.22-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.23.22-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1484",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1484"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1484"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1484"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433259"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-quby27cpefwz.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3870"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1484"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1484"
        }
      ],
      "published": "2026-01-27T14:15:56+00:00",
      "updated": "2026-06-17T10:15:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-177.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1485",
      "ratings": [
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        124
      ],
      "description": "A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1485"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1485"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1485"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433325"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-hui7k8rsmbsl.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3871"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1485"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1485"
        }
      ],
      "published": "2026-01-27T14:15:56+00:00",
      "updated": "2026-06-17T10:15:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-177.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1489",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1489"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1489"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1489"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433348"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-h6zf92f0298p.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3872"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1489"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1489"
        }
      ],
      "published": "2026-01-27T15:15:57+00:00",
      "updated": "2026-06-17T10:15:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-177.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1502",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1502"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/11/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1502"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69"
        },
        {
          "url": "https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53"
        },
        {
          "url": "https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e"
        },
        {
          "url": "https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed"
        },
        {
          "url": "https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec"
        },
        {
          "url": "https://github.com/python/cpython/issues/146211"
        },
        {
          "url": "https://github.com/python/cpython/pull/146212"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-1502.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1502"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1502"
        }
      ],
      "published": "2026-04-10T18:16:40+00:00",
      "updated": "2026-08-13T01:16:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-15146",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget\u2019s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-15146"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15146"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b"
        },
        {
          "url": "https://kb.cert.org/vuls/id/564823"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15146"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8572-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15146"
        },
        {
          "url": "https://www.kb.cert.org/vuls/id/564823"
        }
      ],
      "published": "2026-07-10T19:17:20+00:00",
      "updated": "2026-07-15T19:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.19.5-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-16118",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
      "recommendation": "Upgrade glib2 to version 2.56.4-178.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-16118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:64799"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:64800"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66451"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67956"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70636"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71403"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71404"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71405"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72394"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72399"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72502"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73859"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73909"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73929"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73959"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73960"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73961"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73962"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74359"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74360"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74361"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74362"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74363"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74364"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74365"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74450"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74458"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74459"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74460"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74461"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74462"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74463"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74674"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74677"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74678"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74679"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74681"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74683"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74685"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74687"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74688"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74771"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75652"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75654"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75655"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75657"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75658"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75659"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75660"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76042"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:79357"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16118"
        },
        {
          "url": "https://bugzilla.redhat.com/2501732"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501732"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-16118"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-64800.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:64800"
        },
        {
          "url": "https://gitlab.freedesktop.org/xdg/xdgmime/-/work_items/41"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/work_items/3992"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-16118.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-66451-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16118"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8794-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16118"
        }
      ],
      "published": "2026-07-17T20:17:16+00:00",
      "updated": "2026-10-09T02:17:02+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-177.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-16599",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        606
      ],
      "description": "GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation.\n\n\nThis issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-16599"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16599"
        },
        {
          "url": "https://cert.pl/en/posts/2026/08/CVE-2026-16599"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/e9697d98e7249b0f68a6be040a4f3dcc5bc101fa"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16599"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16599"
        }
      ],
      "published": "2026-08-25T15:16:30+00:00",
      "updated": "2026-08-28T15:26:19+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.19.5-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-1757",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        401
      ],
      "description": "A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2435940"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1009"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1757"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8460-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1757"
        }
      ],
      "published": "2026-02-02T13:15:58+00:00",
      "updated": "2026-09-01T12:17:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-18238",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        126,
        1288
      ],
      "description": "The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers.  A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18238"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18238"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/b9590d482986d64673712460aae1d48d11fa0473"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18238"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18238"
        }
      ],
      "published": "2026-09-05T19:16:55+00:00",
      "updated": "2026-09-08T19:20:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14",
          "versions": [
            {
              "version": "14:1.9.1-5.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18313",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        401
      ],
      "description": "rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use.  A malicious client can cause the server to leak memory substantially faster.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18313"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18313"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18313"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18313"
        }
      ],
      "published": "2026-09-05T19:16:55+00:00",
      "updated": "2026-09-08T19:20:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14",
          "versions": [
            {
              "version": "14:1.9.1-5.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18374",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18374"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/08/27/6"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18374"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18374"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34574"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0015"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18374"
        }
      ],
      "published": "2026-08-27T20:17:03+00:00",
      "updated": "2026-09-03T16:43:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18477",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        367
      ],
      "description": "A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows\u2014including extracting into a newly created directory without using the -P option do not mitigate the issue.",
      "recommendation": "Upgrade tar to version 2:1.30-13.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18477"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49361"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61581"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61586"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61783"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70390"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18477"
        },
        {
          "url": "https://bugzilla.redhat.com/2455360"
        },
        {
          "url": "https://bugzilla.redhat.com/2509735"
        },
        {
          "url": "https://bugzilla.redhat.com/2509843"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455360"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509735"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509843"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18477"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18508"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5704"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-61581.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:61581"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-18477.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70390.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18477"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18477"
        }
      ],
      "published": "2026-08-03T17:16:33+00:00",
      "updated": "2026-09-22T22:17:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-18503",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        1176
      ],
      "description": "Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff().",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18503"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18503"
        },
        {
          "url": "https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82"
        },
        {
          "url": "https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9"
        },
        {
          "url": "https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a"
        },
        {
          "url": "https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024"
        },
        {
          "url": "https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b"
        },
        {
          "url": "https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4"
        },
        {
          "url": "https://github.com/python/cpython/issues/98820"
        },
        {
          "url": "https://github.com/python/cpython/pull/153694"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18503"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18503"
        }
      ],
      "published": "2026-08-10T14:17:21+00:00",
      "updated": "2026-08-18T15:04:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18508",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        59
      ],
      "description": "A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.",
      "recommendation": "Upgrade tar to version 2:1.30-13.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18508"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50807"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61581"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61586"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61783"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70390"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18508"
        },
        {
          "url": "https://bugzilla.redhat.com/2455360"
        },
        {
          "url": "https://bugzilla.redhat.com/2509735"
        },
        {
          "url": "https://bugzilla.redhat.com/2509843"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455360"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509735"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509843"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18477"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18508"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5704"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-61581.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:61581"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-18508.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70390.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18508"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18508"
        }
      ],
      "published": "2026-08-03T16:16:28+00:00",
      "updated": "2026-09-22T22:17:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-18739",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18739"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56984"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18739"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2510737"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18739"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18739"
        }
      ],
      "published": "2026-08-04T06:16:30+00:00",
      "updated": "2026-08-31T18:17:14+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18-1.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18743",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        131
      ],
      "description": "A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18743"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56984"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18743"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2510809"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18743"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18743"
        }
      ],
      "published": "2026-09-01T02:16:57+00:00",
      "updated": "2026-09-08T23:17:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18-1.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18839",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        191
      ],
      "description": "An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18839"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:77932"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2511010"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18839"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18839"
        }
      ],
      "published": "2026-08-05T21:16:57+00:00",
      "updated": "2026-10-08T15:17:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18-1.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18924",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18924"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18924"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-18924.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-18924.json"
        },
        {
          "url": "https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6"
        },
        {
          "url": "https://hackerone.com/reports/3916059"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18924"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8820-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18924"
        }
      ],
      "published": "2026-09-06T18:17:20+00:00",
      "updated": "2026-09-15T07:16:27+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-19445",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-19445"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/09/30/17"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:77028"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-19445"
        },
        {
          "url": "https://bugzilla.redhat.com/2544127"
        },
        {
          "url": "https://bugzilla.redhat.com/2544138"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2544127"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2544138"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19553"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-77028.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:77028"
        },
        {
          "url": "https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d"
        },
        {
          "url": "https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b"
        },
        {
          "url": "https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7"
        },
        {
          "url": "https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8"
        },
        {
          "url": "https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698"
        },
        {
          "url": "https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c"
        },
        {
          "url": "https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b"
        },
        {
          "url": "https://github.com/python/cpython/issues/156293"
        },
        {
          "url": "https://github.com/python/cpython/pull/158504"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-19445.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-77028.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19445"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19445"
        }
      ],
      "published": "2026-09-30T17:16:45+00:00",
      "updated": "2026-10-03T01:17:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-19542",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-19542"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-19542"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19542"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34506"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19542"
        }
      ],
      "published": "2026-09-14T18:17:46+00:00",
      "updated": "2026-09-18T18:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-19553",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        297
      ],
      "description": "ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-19553"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/09/30/16"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:77028"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-19553"
        },
        {
          "url": "https://bugzilla.redhat.com/2544127"
        },
        {
          "url": "https://bugzilla.redhat.com/2544138"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2544127"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2544138"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19553"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-77028.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:77028"
        },
        {
          "url": "https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96"
        },
        {
          "url": "https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf"
        },
        {
          "url": "https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082"
        },
        {
          "url": "https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed"
        },
        {
          "url": "https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced"
        },
        {
          "url": "https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80"
        },
        {
          "url": "https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062"
        },
        {
          "url": "https://github.com/python/cpython/issues/156793"
        },
        {
          "url": "https://github.com/python/cpython/pull/158503"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-19553.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-77028.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19553"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19553"
        }
      ],
      "published": "2026-09-30T17:16:45+00:00",
      "updated": "2026-10-03T01:17:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-19617",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        770
      ],
      "description": "A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This vulnerability results in a Denial of Service (DoS) for affected systems.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-19617"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73989"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-19617"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2514626"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19617"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19617"
        }
      ],
      "published": "2026-08-14T06:17:14+00:00",
      "updated": "2026-10-02T14:17:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8",
          "versions": [
            {
              "version": "8:1.02.181-15.el8_10.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8",
          "versions": [
            {
              "version": "8:1.02.181-15.el8_10.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-1965",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        305
      ],
      "description": "libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1965"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1965"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-1965.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-1965.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-1965.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1965"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8084-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1965"
        }
      ],
      "published": "2026-03-11T11:15:59+00:00",
      "updated": "2026-09-15T07:16:27+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-19672",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        22
      ],
      "description": "The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-19672"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/08/25/10"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-19672"
        },
        {
          "url": "https://github.com/python/cpython/pull/156000"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19672"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19672"
        }
      ],
      "published": "2026-08-19T16:17:06+00:00",
      "updated": "2026-08-28T21:16:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-22185",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125,
        191
      ],
      "description": "OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-22185"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-22185"
        },
        {
          "url": "https://bugs.openldap.org/show_bug.cgi?id=10421"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22185"
        },
        {
          "url": "https://seclists.org/fulldisclosure/2026/Jan/5"
        },
        {
          "url": "https://seclists.org/fulldisclosure/2026/Jan/8"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22185"
        },
        {
          "url": "https://www.openldap.org/"
        },
        {
          "url": "https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline"
        }
      ],
      "published": "2026-01-07T21:16:01+00:00",
      "updated": "2026-06-17T10:19:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.4.46-21.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-22795",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        754
      ],
      "description": "Issue summary: An invalid or NULL pointer dereference can happen in\nan application processing a malformed PKCS#12 file.\n\nImpact summary: An application processing a malformed PKCS#12 file can be\ncaused to dereference an invalid or NULL pointer on memory read, resulting\nin a Denial of Service.\n\nA type confusion vulnerability exists in PKCS#12 parsing code where\nan ASN1_TYPE union member is accessed without first validating the type,\ncausing an invalid pointer read.\n\nThe location is constrained to a 1-byte address space, meaning any\nattempted pointer manipulation can only target addresses between 0x00 and 0xFF.\nThis range corresponds to the zero page, which is unmapped on most modern\noperating systems and will reliably result in a crash, leading only to a\nDenial of Service. Exploiting this issue also requires a user or application\nto process a maliciously crafted PKCS#12 file. It is uncommon to accept\nuntrusted PKCS#12 files in applications as they are usually used to store\nprivate keys which are trusted by definition. For these reasons, the issue\nwas assessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-22795"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-22795"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-3vqq-45qg-2xf6"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2502e7b7d4c0cf4f972a881641fe09edc67aeec4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/572844beca95068394c916626a6d3a490f831a49"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7bbca05be55b129651d9df4bdb92becc45002c12"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eeee3cbd4d682095ed431052f00403004596373e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ef2fb66ec571564d64d1c74a12e388a2a54d05d2"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-22795.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22795"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22795"
        }
      ],
      "published": "2026-01-27T16:16:35+00:00",
      "updated": "2026-06-17T10:20:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-22796",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        754
      ],
      "description": "Issue summary: A type confusion vulnerability exists in the signature\nverification of signed PKCS#7 data where an ASN1_TYPE union member is\naccessed without first validating the type, causing an invalid or NULL\npointer dereference when processing malformed PKCS#7 data.\n\nImpact summary: An application performing signature verification of PKCS#7\ndata or calling directly the PKCS7_digest_from_attributes() function can be\ncaused to dereference an invalid or NULL pointer when reading, resulting in\na Denial of Service.\n\nThe function PKCS7_digest_from_attributes() accesses the message digest attribute\nvalue without validating its type. When the type is not V_ASN1_OCTET_STRING,\nthis results in accessing invalid memory through the ASN1_TYPE union, causing\na crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nsigned PKCS#7 to an application that verifies it. The impact of the\nexploit is just a Denial of Service, the PKCS7 API is legacy and applications\nshould be using the CMS API instead. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#7 parsing implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-22796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-22796"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-r9hf-rxjm-gv2f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2502e7b7d4c0cf4f972a881641fe09edc67aeec4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/572844beca95068394c916626a6d3a490f831a49"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7bbca05be55b129651d9df4bdb92becc45002c12"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eeee3cbd4d682095ed431052f00403004596373e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ef2fb66ec571564d64d1c74a12e388a2a54d05d2"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-22796.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22796"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22796"
        }
      ],
      "published": "2026-01-27T16:16:35+00:00",
      "updated": "2026-06-17T10:20:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-2297",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        668
      ],
      "description": "The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-2297"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/05/6"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-2297"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/482d6f8bdba9da3725d272e8bb4a2d25fb6a603e"
        },
        {
          "url": "https://github.com/python/cpython/commit/69ddd9bb2cc4bd69b1565647c18659c6a789ccd9"
        },
        {
          "url": "https://github.com/python/cpython/commit/876858c9f65d9ab656c7fa639f268ce7856d89dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/a51b1b512de1d56b3714b65628a2eae2b07e535e"
        },
        {
          "url": "https://github.com/python/cpython/commit/c70adad78caeeea33f92f560ecb93331ca11bf66"
        },
        {
          "url": "https://github.com/python/cpython/commit/e58e9802b9bec5cdbf48fc9bf1da5f4fda482e86"
        },
        {
          "url": "https://github.com/python/cpython/issues/145506"
        },
        {
          "url": "https://github.com/python/cpython/pull/145507"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-2297.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2297"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2297"
        }
      ],
      "published": "2026-03-04T23:16:10+00:00",
      "updated": "2026-08-13T01:16:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-23865",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-23865"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/03/8"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9689"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9693"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-23865"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2443891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460038"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460039"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460040"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460041"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460042"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460043"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460044"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22007"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22016"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22018"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22021"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23865"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34268"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34282"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-9693.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:9689"
        },
        {
          "url": "https://github.com/advisories/GHSA-878v-mxg6-vj8f"
        },
        {
          "url": "https://gitlab.com/freetype/freetype/-/commit/fc85a255849229c024c8e65f536fe1875d84841c"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-23865.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-9693.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23865"
        },
        {
          "url": "https://sourceforge.net/projects/freetype/files/freetype2/2.14.2"
        },
        {
          "url": "https://sourceforge.net/projects/freetype/files/freetype2/2.14.2/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8086-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8327-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8328-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8330-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8331-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8332-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8333-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8334-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8339-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8341-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23865"
        },
        {
          "url": "https://www.facebook.com/security/advisories/cve-2026-23865"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2026.html#AppendixJAVA"
        }
      ],
      "published": "2026-03-02T17:16:32+00:00",
      "updated": "2026-06-17T10:22:13+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.1-10.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-24515",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-24515"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-24515"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1131"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24515"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8022-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8022-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8023-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24515"
        }
      ],
      "published": "2026-01-23T08:16:01+00:00",
      "updated": "2026-06-17T10:23:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-24883",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-24883"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-24883"
        },
        {
          "url": "https://dev.gnupg.org/T8049"
        },
        {
          "url": "https://github.com/advisories/GHSA-7246-cvp4-g68w"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24883"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24883"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/01/27/8"
        }
      ],
      "published": "2026-01-27T19:16:16+00:00",
      "updated": "2026-06-17T10:23:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.2.20-4.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-25068",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        129
      ],
      "description": "alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-25068"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-25068"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/commit/5f7fe33002d2d98d84f72e381ec2cccc0d5d3d40"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/02/msg00008.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25068"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8044-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8044-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25068"
        },
        {
          "url": "https://www.vulncheck.com/advisories/alsa-lib-topology-decoder-heap-based-buffer-overflow"
        }
      ],
      "published": "2026-01-29T20:16:10+00:00",
      "updated": "2026-06-17T10:24:04+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.2.10-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-25645",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        377
      ],
      "description": "Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call `extract_zipped_paths()` directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-25645"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-25645"
        },
        {
          "url": "https://github.com/psf/requests"
        },
        {
          "url": "https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7"
        },
        {
          "url": "https://github.com/psf/requests/releases/tag/v2.33.0"
        },
        {
          "url": "https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25645"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8825-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25645"
        }
      ],
      "published": "2026-03-25T17:16:52+00:00",
      "updated": "2026-06-17T10:25:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-27171",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        1284
      ],
      "description": "zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27171"
        },
        {
          "url": "https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit"
        },
        {
          "url": "https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/"
        },
        {
          "url": "https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27171"
        },
        {
          "url": "https://github.com/advisories/GHSA-h858-mf2m-8jf4"
        },
        {
          "url": "https://github.com/madler/zlib/issues/904"
        },
        {
          "url": "https://github.com/madler/zlib/releases/tag/v1.3.2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27171"
        },
        {
          "url": "https://ostif.org/zlib-audit-complete"
        },
        {
          "url": "https://ostif.org/zlib-audit-complete/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8706-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27171"
        }
      ],
      "published": "2026-02-18T04:16:01+00:00",
      "updated": "2026-06-17T10:26:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.2.11-25.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-27456",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        59,
        269,
        367
      ],
      "description": "util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27456"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27456"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27456"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-jgcxwcxt3sxd.toml"
        },
        {
          "url": "https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4"
        },
        {
          "url": "https://github.com/util-linux/util-linux/releases/tag/v2.41.4"
        },
        {
          "url": "https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27456"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8702-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27456"
        }
      ],
      "published": "2026-04-03T22:16:25+00:00",
      "updated": "2026-07-24T22:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28387",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        416
      ],
      "description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages.  These SMTP (or other similar) clients are not vulnerable\nto this issue.  Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28387"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28387"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28387"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28387"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:20+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28388",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28388"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28388"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28388"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28388"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:20+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28389",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28389"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28389"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-7x88-9hgc-69gf"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28389"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28389"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:21+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-29111",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        269
      ],
      "description": "systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-29111"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29111"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19213"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-29111"
        },
        {
          "url": "https://bugzilla.redhat.com/2450505"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450505"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29111"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19213.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19213"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.9.0/BRSA-jk0fvdm3ylf0.toml"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8"
        },
        {
          "url": "https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-29111.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19213.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29111"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8119-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8119-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-29111"
        }
      ],
      "published": "2026-03-23T22:16:26+00:00",
      "updated": "2026-06-17T10:29:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.19",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.19",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.19",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. systemd-libs ships in the base image but systemd is not run as PID 1 or an active service in CP's containers, so the vulnerable IPC handling path is never reached."
      }
    },
    {
      "id": "CVE-2026-31789",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-31789"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-31789"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-j79m-9jxq-788r"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31789"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31789"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:21+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-31911",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        617
      ],
      "description": "libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode.  In particular uncommon use cases a crafted filter program can terminate the OS process.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-31911"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-31911"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31911"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31911"
        }
      ],
      "published": "2026-09-05T19:16:55+00:00",
      "updated": "2026-09-08T19:20:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14",
          "versions": [
            {
              "version": "14:1.9.1-5.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-31912",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "cwes": [
        125,
        823,
        1285
      ],
      "description": "libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer.  In particular uncommon use cases a crafted filter program can cause the interpreter to try reading the OS process memory in the 32GiB around the buffer on 64-bit architectures and in the entire address space on 32-bit architectures.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-31912"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-31912"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31912"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31912"
        }
      ],
      "published": "2026-09-05T19:16:55+00:00",
      "updated": "2026-09-08T19:20:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14",
          "versions": [
            {
              "version": "14:1.9.1-5.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-3276",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        407
      ],
      "description": "unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3276"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/06/03/15"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3276"
        },
        {
          "url": "https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0"
        },
        {
          "url": "https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598"
        },
        {
          "url": "https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f"
        },
        {
          "url": "https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32"
        },
        {
          "url": "https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066"
        },
        {
          "url": "https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f"
        },
        {
          "url": "https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc"
        },
        {
          "url": "https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c"
        },
        {
          "url": "https://github.com/python/cpython/issues/149079"
        },
        {
          "url": "https://github.com/python/cpython/pull/149080"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3276"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3276"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/06/03/15"
        }
      ],
      "published": "2026-06-03T16:16:29+00:00",
      "updated": "2026-08-13T01:16:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32776",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32776"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32776"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1158"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1159"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32776"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8790-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32776"
        }
      ],
      "published": "2026-03-16T14:19:44+00:00",
      "updated": "2026-07-14T13:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32777",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        835
      ],
      "description": "libexpat before 2.7.5 allows an infinite loop while parsing DTD content.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32777"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32777"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/issues/1161"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1159"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1162"
        },
        {
          "url": "https://issues.oss-fuzz.com/issues/486993411"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32777"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8790-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32777"
        }
      ],
      "published": "2026-03-16T14:19:44+00:00",
      "updated": "2026-07-14T13:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32778",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32778"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32778"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1159"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1163"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32778"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8790-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32778"
        }
      ],
      "published": "2026-03-16T14:19:44+00:00",
      "updated": "2026-07-14T13:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32792",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125,
        166
      ],
      "description": "NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt query could underflow Unbound's DNSCrypt packet reading procedure that may lead to heap overflow. A malicious actor can exploit the vulnerability with a single bad DNSCrypt query that its decrypted plaintext consists entirely of '0x00' bytes and does not contain the expected '0x80' marker. Unbound would then start reading more bytes than necessary until it finds a non-'0x00' byte. Based on the underlying memory allocator and the memory layout, it could lead to heap overflow while reading followed by a crash. Likelihood of a crash is low, since it relies heavily on the underlying memory allocator and the memory layout. If the heap overflow does not happen, Unbound's later packet checks will deny the packet. Unbound 1.25.1 contains a patch with a fix to bound reading in the given buffer space.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32792"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32792"
        },
        {
          "url": "https://nlnetlabs.nl/news/2026/May/20/unbound-1.25.1-released/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32792"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8282-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32792"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-32792.txt"
        }
      ],
      "published": "2026-05-20T10:16:26+00:00",
      "updated": "2026-07-24T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-33056",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        61
      ],
      "description": "tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to check whether a path that already exists is a directory. Because fs::metadata() follows symbolic links, a crafted tarball containing a symlink entry followed by a directory entry with the same name causes the crate to treat the symlink target as a valid existing directory \u2014 and subsequently apply chmod to it. This allows an attacker to modify the permissions of arbitrary directories outside the extraction root. This issue has been fixed in version 0.4.45.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33056"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33056"
        },
        {
          "url": "https://github.com/alexcrichton/tar-rs"
        },
        {
          "url": "https://github.com/alexcrichton/tar-rs/commit/17b1fd84e632071cb8eef9d3709bf347bd266446"
        },
        {
          "url": "https://github.com/alexcrichton/tar-rs/security/advisories/GHSA-j4xf-2g29-59ph"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33056"
        },
        {
          "url": "https://rustsec.org/advisories/RUSTSEC-2026-0067.html"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8138-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8139-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8168-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33056"
        }
      ],
      "published": "2026-03-20T08:16:11+00:00",
      "updated": "2026-06-17T10:36:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-34180",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive\nelement whose content exceeds 2 gigabytes in length may cause a heap buffer\nover-read on 64-bit Unix and Unix-like platforms.\n\nImpact summary: The heap buffer over-read may crash the application (Denial of\nService) or to load into the decoded ASN.1 object contents of memory beyond the\nend of the input buffer.  More typically such ASN.1 elements would instead be\ntruncated.\n\nAn integer truncation in OpenSSL's ASN.1 decoder causes the content length of\nan ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the\nworst case the truncated length is treated as a request to scan the binary\ncontent for a terminating zero byte, possibly causing OpenSSL to read either\nless than or beyond the end of the allocated buffer.\n\nApplications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or\nany other d2i_* decoding function are affected. OpenSSL's own command-line\ntools are not vulnerable, as data read through the BIO layer is checked before\nit reaches the affected code. The issue only affects 64-bit Unix and Unix-like\nplatforms; 32-bit platforms and 64-bit Windows are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34180"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34180"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-3c8f-qq7h-7qv6"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/1c6908e4fa5fa568752221d8eaf561a809751e5d"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/cbe418ae978539cf14a398a207dba834c0e93e83"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d93853c42110d6319e3df07842b488cb9f7ac5ff"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/da5d62af75f69d6fbf7803743d7c56ac75461e43"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f696c73c3e61b8c502d040af62e690c060908a16"
        },
        {
          "url": "https://github.com/openssl/security/commit/1c6908e4fa5fa568752221d8eaf561a809751e5d"
        },
        {
          "url": "https://github.com/openssl/security/commit/cbe418ae978539cf14a398a207dba834c0e93e83"
        },
        {
          "url": "https://github.com/openssl/security/commit/d93853c42110d6319e3df07842b488cb9f7ac5ff"
        },
        {
          "url": "https://github.com/openssl/security/commit/da5d62af75f69d6fbf7803743d7c56ac75461e43"
        },
        {
          "url": "https://github.com/openssl/security/commit/f696c73c3e61b8c502d040af62e690c060908a16"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-34180.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34180"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34180"
        }
      ],
      "published": "2026-06-09T17:17:04+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-34743",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        122
      ],
      "description": "XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34743"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/31/13"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:64787"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34743"
        },
        {
          "url": "https://bugzilla.redhat.com/2454589"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2454589"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34743"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-64787.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:64787"
        },
        {
          "url": "https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87"
        },
        {
          "url": "https://github.com/tukaani-project/xz/releases/tag/v5.8.3"
        },
        {
          "url": "https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-34743.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-64787-0.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/07/msg00034.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34743"
        },
        {
          "url": "https://tukaani.org/xz/index-append-overflow.html"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8362-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34743"
        }
      ],
      "published": "2026-04-02T19:21:33+00:00",
      "updated": "2026-07-24T21:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "5.2.4-4.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-34757",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from png_get_PLTE, png_get_tRNS, or png_get_hIST back into the corresponding setter on the same png_struct/png_info pair causes the setter to read from freed memory and copy its contents into the replacement buffer. The setter frees the internal buffer before copying from the caller-supplied pointer, which now dangles. The freed region may contain stale data (producing silently corrupted chunk metadata) or data from subsequent heap allocations (leaking unrelated heap contents into the chunk struct). This vulnerability is fixed in 1.6.57.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34757"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34757"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc"
        },
        {
          "url": "https://github.com/pnggroup/libpng/issues/836"
        },
        {
          "url": "https://github.com/pnggroup/libpng/issues/837"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-6fr7-g8h7-v645"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/05/msg00017.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34757"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8251-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8639-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34757"
        }
      ],
      "published": "2026-04-09T15:16:11+00:00",
      "updated": "2026-06-17T10:39:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.6.34-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3479",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        22
      ],
      "description": "DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3479"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3479"
        },
        {
          "url": "https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe"
        },
        {
          "url": "https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7"
        },
        {
          "url": "https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943"
        },
        {
          "url": "https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c"
        },
        {
          "url": "https://github.com/python/cpython/issues/146121"
        },
        {
          "url": "https://github.com/python/cpython/pull/146122"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3479"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3479"
        }
      ],
      "published": "2026-03-18T19:16:06+00:00",
      "updated": "2026-06-17T10:43:39+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-35189",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-35189"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-35189"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35189"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-35189"
        }
      ],
      "published": "2026-09-29T16:17:07+00:00",
      "updated": "2026-10-08T01:01:54+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-35191",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        440
      ],
      "description": "Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-35191"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-35191"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35191"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-35191"
        }
      ],
      "published": "2026-09-29T16:17:07+00:00",
      "updated": "2026-10-08T01:02:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-3644",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        20,
        116
      ],
      "description": "The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3644"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/3974092b037f9a3b000fb15b48ea61ce3b25d330"
        },
        {
          "url": "https://github.com/python/cpython/commit/556aa098e738b127c714866f819b4abe2f7593d8"
        },
        {
          "url": "https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4"
        },
        {
          "url": "https://github.com/python/cpython/commit/62ceb396fcbe69da1ded3702de586f4072b590dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/dae4b1a21f8df4570e30986affd61bbe4ade4cef"
        },
        {
          "url": "https://github.com/python/cpython/issues/145599"
        },
        {
          "url": "https://github.com/python/cpython/pull/145600"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3644.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3644"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8744-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3644"
        }
      ],
      "published": "2026-03-16T18:16:09+00:00",
      "updated": "2026-08-13T01:16:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3731",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        119,
        125
      ],
      "description": "A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3731"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3731"
        },
        {
          "url": "https://gitlab.com/libssh/libssh-mirror/-/commit/855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3731"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8093-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8093-2"
        },
        {
          "url": "https://vuldb.com/?ctiid.349709"
        },
        {
          "url": "https://vuldb.com/?id.349709"
        },
        {
          "url": "https://vuldb.com/?submit.767120"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3731"
        },
        {
          "url": "https://www.libssh.org/files/0.12/libssh-0.12.0.tar.xz"
        },
        {
          "url": "https://www.libssh.org/security/advisories/libssh-2026-sftp-extensions.txt"
        }
      ],
      "published": "2026-03-08T11:15:50+00:00",
      "updated": "2026-06-17T10:44:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh-config@0.9.6-17.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libssh@0.9.6-17.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-3783",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        522
      ],
      "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\n\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3783"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/11/2"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3783"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3783.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3783.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://github.com/advisories/GHSA-8whr-249c-vfjp"
        },
        {
          "url": "https://hackerone.com/reports/3583983"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3783.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3783"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8084-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3783"
        }
      ],
      "published": "2026-03-11T11:16:00+00:00",
      "updated": "2026-09-15T07:16:27+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-3784",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        305
      ],
      "description": "curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3784"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/11/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3784"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3784.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3784.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-5q3w-6p3j-mw6p"
        },
        {
          "url": "https://hackerone.com/reports/3584903"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3784.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3784"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8084-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3784"
        }
      ],
      "published": "2026-03-11T11:16:00+00:00",
      "updated": "2026-09-15T07:16:27+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3832",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        179
      ],
      "description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3832"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13274"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20612"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20613"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26409"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29197"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72502"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3832"
        },
        {
          "url": "https://bugzilla.redhat.com/2445763"
        },
        {
          "url": "https://bugzilla.redhat.com/2450624"
        },
        {
          "url": "https://bugzilla.redhat.com/2450625"
        },
        {
          "url": "https://bugzilla.redhat.com/2467279"
        },
        {
          "url": "https://bugzilla.redhat.com/2467289"
        },
        {
          "url": "https://bugzilla.redhat.com/2467437"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445762"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450624"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450625"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467279"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467289"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467437"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467441"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467451"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467678"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467686"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33845"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33846"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3832"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3833"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42009"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42015"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5260"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5419"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-20612.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:20612"
        },
        {
          "url": "https://gitlab.com/gnutls/gnutls/-/issues/1801"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3832.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50346.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3832"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8284-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3832"
        },
        {
          "url": "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-12"
        }
      ],
      "published": "2026-04-30T18:16:30+00:00",
      "updated": "2026-09-29T01:16:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.16-8.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-40467",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "Use After Free vulnerability has been found in \"io.c\" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects\u00a0gawk in versions 5.4.0 and below.",
      "recommendation": "Upgrade gawk to version 4.2.1-5.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40467"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73512"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40467"
        },
        {
          "url": "https://bugzilla.redhat.com/2499655"
        },
        {
          "url": "https://bugzilla.redhat.com/2499657"
        },
        {
          "url": "https://bugzilla.redhat.com/2499658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499658"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-40467"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=a2d18c74109e41bec29a23098eba2e00057286d8"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40553"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-73512.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:73512"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-40467.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-73512.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40467"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8588-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40467"
        }
      ],
      "published": "2026-07-13T13:16:36+00:00",
      "updated": "2026-07-14T01:13:59+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.2.1-4.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-40468",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Integer overflow vulnerability has been found in \"builtin.c\" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects\u00a0gawk in versions 5.4.0 and below.",
      "recommendation": "Upgrade gawk to version 4.2.1-5.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40468"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73512"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40468"
        },
        {
          "url": "https://bugzilla.redhat.com/2499655"
        },
        {
          "url": "https://bugzilla.redhat.com/2499657"
        },
        {
          "url": "https://bugzilla.redhat.com/2499658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499658"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-40467"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40553"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-73512.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:73512"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-40468.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-73512.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40468"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8588-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40468"
        }
      ],
      "published": "2026-07-13T13:16:36+00:00",
      "updated": "2026-07-14T01:12:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.2.1-4.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-40930",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        436
      ],
      "description": "LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG parser clear the chunk-header flag without consuming the chunk body and CRC, allowing attacker-controlled bytes inside an ignored ancillary chunk to be reinterpreted as a fresh chunk header on the next call to `png_process_data`. Commit faf06924688b62d7c1654b5ceddedbde66ffadb4 fixes the issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40930"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/15/21"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40930"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/faf06924688b62d7c1654b5ceddedbde66ffadb4"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-c4v6-gxrq-6g2x"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40930"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8639-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40930"
        }
      ],
      "published": "2026-06-04T16:16:36+00:00",
      "updated": "2026-07-22T20:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.6.34-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libpng@1.6.34-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-4105",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        284
      ],
      "description": "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4105"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7299"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4105"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447262"
        },
        {
          "url": "https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4105"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4105"
        }
      ],
      "published": "2026-03-13T19:55:13+00:00",
      "updated": "2026-09-01T13:19:38+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.19",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.19",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.19",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/systemd@239-82.el8_10.19?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41080",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        331
      ],
      "description": "libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41080"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/26/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41080"
        },
        {
          "url": "https://blog.hartwork.org/posts/expat-2-8-0-released/"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/issues/47"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1183"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41080"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8520-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8790-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41080"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/26/1"
        }
      ],
      "published": "2026-04-16T17:16:54+00:00",
      "updated": "2026-07-14T13:18:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41990",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41990"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41990"
        },
        {
          "url": "https://dev.gnupg.org/T8208"
        },
        {
          "url": "https://github.com/advisories/GHSA-78pv-qq8x-94px"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41990"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8319-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41990"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/21/1"
        }
      ],
      "published": "2026-04-23T05:16:05+00:00",
      "updated": "2026-06-17T10:47:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.8.5-8.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libgcrypt@1.8.5-8.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-4224",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "When an Expat parser with a registered ElementDeclHandler parses an inline\ndocument type definition containing a deeply nested content model a C stack\noverflow occurs.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4224"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/16/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4224"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/196edfb06a7458377d4d0f4b3cd41724c1f3bd4a"
        },
        {
          "url": "https://github.com/python/cpython/commit/24ce88b285f56ee11626cf5e472af3cd8cc7c621"
        },
        {
          "url": "https://github.com/python/cpython/commit/642865ddf4b232da1f3b1f7abcfa3254c4bfe785"
        },
        {
          "url": "https://github.com/python/cpython/commit/af856a7177326ac25d9f66cc6dd28b554d914fee"
        },
        {
          "url": "https://github.com/python/cpython/commit/e0a8a6da90597a924b300debe045cdb4628ee1f3"
        },
        {
          "url": "https://github.com/python/cpython/commit/eb0e8be3a7e11b87d198a2c3af1ed0eccf532768"
        },
        {
          "url": "https://github.com/python/cpython/issues/145986"
        },
        {
          "url": "https://github.com/python/cpython/pull/145987"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-4224.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/5M7CGUW3XBRY7II4DK43KF7NQQ3TPZ6R/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4224"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8744-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4224"
        }
      ],
      "published": "2026-03-16T18:16:10+00:00",
      "updated": "2026-08-13T01:16:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42250",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "bzip2 contains an off\u2011by\u2011one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out\u2011of\u2011bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch\u00a035d122a3df8b0cc4082a4d89fdc6ee99f375fe67",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42250"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42250"
        },
        {
          "url": "https://cert.pl/en/posts/2026/05/CVE-2026-42250/"
        },
        {
          "url": "https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42250"
        },
        {
          "url": "https://sourceware.org/bzip2/"
        },
        {
          "url": "https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8685-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42250"
        }
      ],
      "published": "2026-05-28T14:16:19+00:00",
      "updated": "2026-06-17T10:47:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.0.6-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42308",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42308"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42308"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-42308"
        },
        {
          "url": "https://github.com/advisories/GHSA-wjx4-4jcj-g98j"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-165.yaml"
        },
        {
          "url": "https://github.com/python-pillow/Pillow"
        },
        {
          "url": "https://github.com/python-pillow/Pillow/pull/9518/changes%20%28suspected%20fix%29"
        },
        {
          "url": "https://github.com/python-pillow/Pillow/releases/tag/12.2.0"
        },
        {
          "url": "https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42308"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8399-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42308"
        }
      ],
      "published": "2026-05-09T06:16:09+00:00",
      "updated": "2026-07-24T21:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42765",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: When a partial-chain certificate verification is enabled\ntogether with OCSP response checking for the whole chain, a NULL dereference\nwill happen if the verified chain does not have a self-signed trusted anchor,\ncrashing the process.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to a\nDenial of Service for an application.\n\nWhen performing OCSP response checking for certificates in the verification\nchain, the code always tries to access the next certificate as the issuer.\nThere is a check for a self-signed certificate. However with the partial\nchain verification enabled when the chain does not have a self-signed trusted\nanchor, the issuer will be NULL for the last certificate in the chain. A NULL\npointer dereference then happens.\n\nThis issue affects only applications which enable both OCSP verification\nof the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial\nchain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate\nverification. Both flags are disabled by default. For that reason, we have\nassigned Low severity to the issue.\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42765"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42765"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/14340b7fa1d444615486bc137014b064e64ec334"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eb345da18ce2216b2f3ade9c2bc23e068487fa97"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42765"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42765"
        }
      ],
      "published": "2026-06-09T17:17:07+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42766",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: A specially crafted password-encrypted CMS message\ncan trigger a NULL pointer dereference during CMS decryption.\n\nImpact summary: This NULL pointer dereference leads to an application crash\nand a Denial of Service.\n\nThe CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as\nOPTIONAL in the ASN.1 specification and may therefore be absent in specially\ncrafted inputs. During the password-based CMS decryption the OpenSSL\nCMS implementation dereferences this field without first checking whether it\nwas present.\n\nAn attacker who supplies such a CMS message to an application performing\npassword-based CMS decryption can trigger an application crash, leading to\na Denial of Service.\n\nApplications that process password-encrypted CMS messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42766"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42766"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-58mv-qqmv-gqgv"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/056d06c1918fafbb98c1c85a02e4c47cc4e199ce"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/12bc26ffb3a2be728c9b86e1cae277de5b33dfa4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3ff64913615d648cfbb6a6f1cf5529ae7ea829d7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ab52d88cb5374876d59aee3c91f9e4ccce2b7ce4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/da26f368732b83e40e9d356fe61c3d3aaab6d2e8"
        },
        {
          "url": "https://github.com/openssl/security/commit/056d06c1918fafbb98c1c85a02e4c47cc4e199ce"
        },
        {
          "url": "https://github.com/openssl/security/commit/12bc26ffb3a2be728c9b86e1cae277de5b33dfa4"
        },
        {
          "url": "https://github.com/openssl/security/commit/3ff64913615d648cfbb6a6f1cf5529ae7ea829d7"
        },
        {
          "url": "https://github.com/openssl/security/commit/ab52d88cb5374876d59aee3c91f9e4ccce2b7ce4"
        },
        {
          "url": "https://github.com/openssl/security/commit/da26f368732b83e40e9d356fe61c3d3aaab6d2e8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42766.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42766"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42766"
        }
      ],
      "published": "2026-06-09T17:17:07+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42768",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        514
      ],
      "description": "Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to\nBleichenbacher-style attack when an attacker is able to provide the CMS or\nS/MIME messages and observe the error code and/or decryption output.\n\nImpact summary: The Bleichenbacher-style attack allows an attacker to use the\nvictim's vulnerable application as a way to decrypt or sign messages with the\nvictim's private RSA key.\n\nThe attack is possible in 2 variants.\n\n1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without\nproviding the recipient certificate. In this case OpenSSL iterates over every\nKeyTransRecipientInfo (KTRI) without stopping at the first success.\n\nAn attacker who authors a message with two KTRI entries \u2014 the first one\nwrapping a real CEK under the victim's public key, the second with an\narbitrary probe ciphertext \u2014 obtains opportunity to iterate the 2nd KTRI to\nget a valid PKCS#1 v1.5 padding if the error code of the application is\navailable.\n\nThat is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an\nadaptive-chosen-ciphertext side channel from which the attacker decrypts any\nRSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under\nit.\n\n2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with\nthe recipient certificate, and the recipient is not found, a random\nkey is substituted.\n\nAn attacker who authors a message and is able to compare both error code and\nthe result of the decryption, can mount a Bleichenbacher oracle.\n\nWe are not aware of any applications that provide a remote attacker\nan opportunity to mount an attack described in these scenarios. We consider\nthe existence of such application very unlikely, and for this reason this\nCVE has been evaluated as Low severity.\n\nTo avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the\ninvoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described\nin draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit\nrejection was explicitly disabled.\n\nThe implicit rejection mechanism always returns a plaintext value,\nthe symmetric key. This result is deterministic for the ciphertext and the\nprivate key.  The length of the decryption result can happen to match the\nlength of the key of the symmetric cipher that was used for the content\nencryption. When a certificate is not provided, the last RecipientInfo\nproducing a key that looks valid will be used. It may cause getting garbage\ncontent on decryption. As a proper way to deal with this a recipient\ncertificate has to be provided to identify the particular RecipientInfo for\ndecryption.\n\nThe FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as\nCMS and S/MIME processing happens outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42768"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42768"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-5m8f-m8jv-3rp3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a2ca7b2d73e0ffc1eae183fe6e1741dac767cb4f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bbb151a83041705d9d001ed2f9c12f5523e1b54d"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/dd68364107a58841c0a2546812518b65d3a23abd"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f04b377be3d821741c86d1f4bf84dee09f3d5c3e"
        },
        {
          "url": "https://github.com/openssl/security/commit/a2ca7b2d73e0ffc1eae183fe6e1741dac767cb4f"
        },
        {
          "url": "https://github.com/openssl/security/commit/bbb151a83041705d9d001ed2f9c12f5523e1b54d"
        },
        {
          "url": "https://github.com/openssl/security/commit/dd68364107a58841c0a2546812518b65d3a23abd"
        },
        {
          "url": "https://github.com/openssl/security/commit/f04b377be3d821741c86d1f4bf84dee09f3d5c3e"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42768.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42768"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42768"
        }
      ],
      "published": "2026-06-09T17:17:08+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42770",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        325
      ],
      "description": "Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42)\npeer key, the peer key is not properly checked for the subgroup membership.\n\nImpact summary: A malicious peer which presents an X9.42 key carrying the\nvictim's p and g parameters, a forged q = r (a small prime factor of the\ncofactor (p\u22121)/q_local), and a public value Y of order r can recover the\nvictim's private key after a small number of key exchange attempts.\n\nWhen EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the\nsubgroup membership check Y^q \u2261 1 (mod p) is performed using the peer's\nown q parameter, not the local key's q. The peer's domain parameters are\nthen matched against the domain parameters of the private key, but the value\nof q is not compared.\n\nA malicious peer who presents an X9.42 key carrying the victim's p, g,\na forged q = r (a small prime factor of the cofactor), and a public\nvalue Y of order r passes all checks. The shared secret then takes only\nr distinct values, leaking priv mod r. Repeating for each small-prime\nfactor of the cofactor and combining via CRT recovers the full private\nkey (Lim\u2013Lee / small-subgroup-confinement attack).\n\nThe realistic attack surface is narrow: principally CMP deployments with\nlong-lived RA/CA DHX keys and bespoke enterprise or government applications\nusing X9.42 DHX static keys with interactive protocols and therefore this\nissue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this\nissue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42770"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42770"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-3cxm-476w-ghm2"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3da5a516cd2635a320ff748503db2cef7c4b0f02"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3ddbb7ab50bd93dfc59cbe08e269a67605aeebdb"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5f452bba2c681423d8fcffd120a19b757ee42e3c"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7fbfde7677ed8808828bf00ff01c937ca04bdda2"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ca2237ab5615641b662183b077f62c08d75e8070"
        },
        {
          "url": "https://github.com/openssl/security/commit/3da5a516cd2635a320ff748503db2cef7c4b0f02"
        },
        {
          "url": "https://github.com/openssl/security/commit/3ddbb7ab50bd93dfc59cbe08e269a67605aeebdb"
        },
        {
          "url": "https://github.com/openssl/security/commit/5f452bba2c681423d8fcffd120a19b757ee42e3c"
        },
        {
          "url": "https://github.com/openssl/security/commit/7fbfde7677ed8808828bf00ff01c937ca04bdda2"
        },
        {
          "url": "https://github.com/openssl/security/commit/ca2237ab5615641b662183b077f62c08d75e8070"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42770.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42770"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42770"
        }
      ],
      "published": "2026-06-09T17:17:08+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42771",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an\napplication to validate a crafted e-mail address, such as during S/MIME\nmessage validation, an out of bounds read can happen.\n\nImpact summary: This out of bounds read will not directly exfiltrate\nthe data read to the attacker so the most likely result is a crash and\na Denial of Service.\n\nAn internal helper function called from X509_VERIFY_PARAM_[set|add]_email()\nused a wrong length when validating the local part of an email address.\nThis could cause the 64 octet limit on the local part of an email address\nto be not enforced, or cause an out of bound read and potentially a crash.\n\nThe bug is reachable via S-MIME validation with a crafted From: address\nsupplied in an email message that can potentially cause a crash.\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42771"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42771"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/6cd187689f8180c1f8a3acde21f88190c4a20de7"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42771"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42771"
        }
      ],
      "published": "2026-06-09T17:17:08+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42772",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        407
      ],
      "description": "Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42772"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42772"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42772"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8861-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42772"
        }
      ],
      "published": "2026-09-29T16:17:07+00:00",
      "updated": "2026-10-08T01:18:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42923",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        407
      ],
      "description": "NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to consult the negative cache for DS records does not take into account the limit on NSEC3 hash calculations introduced in 1.19.1. This leads to degradation of service during the attack. An adversary that controls a DNSSEC signed zone can exploit this by signing NSEC3 records with acceptably high iterations for child delegations and querying a vulnerable Unbound. Unbound will keep performing the allowed hash calculations on the NSEC3 records and will not limit the work by the mitigation introduced in 1.19.1. As a side effect, a global lock for the negative cache will be held for the duration of the hashing, blocking other threads that need to consult the negative cache. Coordinated attacks could raise the vulnerability to denial of service. Unbound 1.25.1 contains a patch with a fix to bound the vulnerable code path with the existing limit for NSEC3 hash calculations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42923"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42923"
        },
        {
          "url": "https://nlnetlabs.nl/news/2026/May/20/unbound-1.25.1-released/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42923"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8282-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42923"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42923.txt"
        }
      ],
      "published": "2026-05-20T10:16:27+00:00",
      "updated": "2026-07-24T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42955",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        672
      ],
      "description": "In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client A/AAAA query can cause Unbound to overwrite the cached expired parent-side glue rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client query is required since Unbound implicitly performs that query. This is a variant of CVE-2026-40622 which only addressed the NS query.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42955"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42955"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42955"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42955"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42955.txt"
        }
      ],
      "published": "2026-07-22T14:17:18+00:00",
      "updated": "2026-07-24T13:56:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42960",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 10,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        349
      ],
      "description": "NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply (i.e., spoofed packet, fragmentation attack) he would be able to poison Unbound's cache. A malicious actor can exploit the possible poisonous effect by injecting RRSets other than NS that are also accompanied by address records in a reply, for example MX. This could be achieved by trying to spoof a reply packet or fragmentation attacks. Unbound would then accept the relative address records in the additional section and cache them if the authority RRSet has enough trust at this point, i.e., in-zone data for the delegation point. Unbound 1.25.1 contains a patch with a fix that disregards address records from the additional section if they are not explicitly relevant only to authority NS records, mitigating the possible poison effect. This is a complement fix to CVE-2025-11411.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42960"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42960"
        },
        {
          "url": "https://nlnetlabs.nl/news/2026/May/20/unbound-1.25.1-released/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42960"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8282-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8282-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42960"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42960.txt"
        }
      ],
      "published": "2026-05-20T10:16:28+00:00",
      "updated": "2026-07-24T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-4360",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        281
      ],
      "description": "In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4360"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4360"
        },
        {
          "url": "https://github.com/python/cpython/commit/0367912be336348b30572f8029cec4a282782d92"
        },
        {
          "url": "https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0"
        },
        {
          "url": "https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301"
        },
        {
          "url": "https://github.com/python/cpython/commit/7ccdbaba2c54250a70d7f25632152df7655a5e0a"
        },
        {
          "url": "https://github.com/python/cpython/commit/cf23b9153181062150d061468b6d24af33fe214f"
        },
        {
          "url": "https://github.com/python/cpython/commit/d2b2f5eacab4dd48446b63340613b05dcbbf0b44"
        },
        {
          "url": "https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e"
        },
        {
          "url": "https://github.com/python/cpython/issues/151987"
        },
        {
          "url": "https://github.com/python/cpython/pull/151988"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4360"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8744-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4360"
        }
      ],
      "published": "2026-06-30T15:16:57+00:00",
      "updated": "2026-08-13T01:16:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-4426",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1335
      ],
      "description": "A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4426"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8944"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4426"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449010"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2897"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4426"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8292-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4426"
        }
      ],
      "published": "2026-03-19T15:16:28+00:00",
      "updated": "2026-09-01T13:19:39+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-4437",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4437"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20597"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4437"
        },
        {
          "url": "https://bugzilla.redhat.com/2449777"
        },
        {
          "url": "https://bugzilla.redhat.com/2449783"
        },
        {
          "url": "https://bugzilla.redhat.com/2453117"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449777"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449783"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2453117"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4046"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4437"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4438"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-20597.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:20597"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-4437.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-500006.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4437"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34014"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8611-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4437"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/03/23/2"
        }
      ],
      "published": "2026-03-20T20:16:49+00:00",
      "updated": "2026-07-14T13:18:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-4438",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        20,
        88
      ],
      "description": "Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4438"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20597"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4438"
        },
        {
          "url": "https://bugzilla.redhat.com/2449777"
        },
        {
          "url": "https://bugzilla.redhat.com/2449783"
        },
        {
          "url": "https://bugzilla.redhat.com/2453117"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449777"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449783"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2453117"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4046"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4437"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4438"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-20597.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:20597"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-4438.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-500006.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4438"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34015"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8611-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4438"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/03/23/2"
        }
      ],
      "published": "2026-03-20T20:16:49+00:00",
      "updated": "2026-07-14T13:18:58+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-44605",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44605"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33507"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44605"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482481"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44605"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44605"
        }
      ],
      "published": "2026-08-05T18:17:11+00:00",
      "updated": "2026-08-31T13:18:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-44608",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        413
      ],
      "description": "NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could result in heap use-after-free and eventual crash. An adversary can exploit the vulnerability if conditions are first met on a vulnerable Unbound, i.e., multi-threaded, an RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers and an ongoing XFR for that RPZ zone. Local RPZ files do not trigger the vulnerability. If the timing is right and an XFR happens at the same time another thread needs to read that RPZ zone, the reader may not hold the lock long enough and the thread applying the XFR may free objects that the reader is about to walk causing the use-after-free. Unbound 1.25.1 contains a patch with a fix to the locking code.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44608"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44608"
        },
        {
          "url": "https://nlnetlabs.nl/news/2026/May/20/unbound-1.25.1-released/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44608"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8282-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44608"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-44608.txt"
        }
      ],
      "published": "2026-05-20T10:16:28+00:00",
      "updated": "2026-07-24T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-44621",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        754
      ],
      "description": "With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could eventually be abruptly terminated if the threshold is reached and libunbound needs to call 'libworker_alloc_cleanup' since the function is absent from the function call allow list. When an application using libunbound sets 'unwanted-reply-threshold' to any non-zero value and the iterator queries an authoritative that replies with enough wrong-transaction-ID UDP datagrams to cross the threshold, the 'libworker_alloc_cleanup' will eventually be called. Since the function is absent from the function call allow list, this leads to a fatal exit of libunbound and eventual termination of the embedding application.Unbound itself is not affected since its relevant function 'worker_alloc_cleanup' is registed in the allow list and proceeds to perform the documented cache flush.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44621"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44621"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44621"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44621"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-44621.txt"
        }
      ],
      "published": "2026-07-22T14:17:18+00:00",
      "updated": "2026-07-24T13:56:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-44687",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        193
      ],
      "description": "In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate labed below a DNSSEC signed zone could be shadowed by the intermediate label's secure NXDOMAIN answer from the parent. This is caused by an off-by-one error in 'harden-below-nxdomain' logic; enabled by default. It effectively bypasses the configuration and the configured stub/forward zone is never contacted. 'harden-below-nxdomain' does an upward DNS cache walk together with a delegation point guard that does not allow NXDOMAIN synthesis above stub/forward zones. The guard tests the domain name but before stripping a label. This results in an iteration where the domain name equals the configured stub/forward zone apex that passes the guard, strips one more label, and probes the cache at the apex's immediate public parent. If that parent has a cached DNSSEC-secure NXDOMAIN, which it will for any private namespace nested two or more labels under a signed public name, the walk returns it and the configured stub/forward upstream is never contacted. This can only be triggered by the query for the intermediate label (between the stub/forward apex and the DNSSEC parent zone).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44687"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44687"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44687"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44687"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-44687.txt"
        }
      ],
      "published": "2026-07-22T14:17:19+00:00",
      "updated": "2026-07-24T13:56:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-46582",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        358
      ],
      "description": "In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later validation treats it as bogus based on NSEC validation. When the resolving thread puts secure on the rrset, and another thread that is on the serve expired path then picks up the updated rrset contents with the secure status for a reply, it can be used to change a specific record, next to a wildcard that could be covered by the wildcard, into the wildcard. A malicious actor can exploit the possible poisonous effect by having any DNSSEC-singed domain (irrelevant to the victim domain) and a CNAME wrapper record that points to a record next to a wildcard (that could be covered by the wildcard). Then quering Unbound for the wildcard sibling record would seed the secure message. A later (after expiry) query for the CNAME wrapper would need to resolve the target sibling record. If the wildcard replay is injected into the response, the wildcard rrset will update the expired sibling record with a secure status before completing proper wildcard validation with NSEC records and eventually treating the CNAME wrapper answer as bogus. The updated poisoned rrset is now secure and points to the wildcard. This vulnerability is explicit for the serve expired path and needs injection of the signed wildcard rrset without the NSEC accompanying rrset.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-46582"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-46582"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46582"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46582"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-46582.txt"
        }
      ],
      "published": "2026-07-22T14:17:19+00:00",
      "updated": "2026-07-24T13:55:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-4873",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        319,
        295
      ],
      "description": "A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4873"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4873"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-4873.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-4873.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-5fgw-rv54-prjx"
        },
        {
          "url": "https://hackerone.com/reports/3621851"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4873"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4873"
        }
      ],
      "published": "2026-05-13T13:01:55+00:00",
      "updated": "2026-09-15T07:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-49919",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H"
        }
      ],
      "cwes": [
        190
      ],
      "description": "In tt_face_colr_blend_layer of ttcolr.c, there is a possible remote code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-49919"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-49919"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49919"
        },
        {
          "url": "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49919"
        }
      ],
      "published": "2026-09-08T19:17:59+00:00",
      "updated": "2026-09-24T15:47:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.1-10.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-50046",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        416
      ],
      "description": "In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The dereference is read-only and the practical impact is a daemon crash resulting in denial of service. A malicious actor that knows a DoT forwarding/stub Unbound's configuration could exploit the vulnerability by quering records in the appropriate zone while keeping Unbound uder pressure so that the jostle logic kicks in. If answers for the vulnerable zone are slow, the likelihood of jostling such queries is higher, although the timing of the jostle needs to be precise. Requirements for a vulnerable Unbound is the existence of a stub/forward zone configured for DoT together with a configured '#authname' suffix on the server identification. The connectivity to the server needs to exhibit a transient failure at the correct time in order to kick off the vulnerable error path.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-50046"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-50046"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50046"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50046"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50046.txt"
        }
      ],
      "published": "2026-07-22T14:17:20+00:00",
      "updated": "2026-07-24T13:55:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-50243",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        348
      ],
      "description": "In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect rule or an RPZ file with an RPZ-IP trigger, the rewriting handler does not check the security status of the upstream answer and can instead rewrite a BOGUS A/AAAA answer to point to an operator's configured IP. If the validator finds an expired or otherwise invalid RRSIG on an answer whose A record falls within a 'response-ip'/RPZ configuration, the answer is still rewritten and given a hard coded security level of INSECURE. This results in the client receiving an INSECURE NOERROR reply rewritten by the operator's configured IP. A malicious actor can exploit the possible poisonous effect by spoofing a BOGUS A/AAAA answer that falls inside the operator's configured subnet rewrites. Such DNSSEC protected answers are then insecurely redirected to the operator's configured target.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-50243"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-50243"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50243"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50243"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50243.txt"
        }
      ],
      "published": "2026-07-22T14:17:20+00:00",
      "updated": "2026-07-24T13:59:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-50248",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "cwes": [
        345
      ],
      "description": "In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA record (no valid RRSIG required) becomes the zone's XFR primary and can replaces the entire zone/the resolver's entire response policy.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-50248"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-50248"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50248"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50248"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50248.txt"
        }
      ],
      "published": "2026-07-22T14:17:20+00:00",
      "updated": "2026-07-24T13:59:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-50251",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        184
      ],
      "description": "In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving seemingly unwanted replies since the remote IP does not match the original source IP of 0.0.0.0/::0. This behavior keeps on looping for the glue records and pushing the counter to the configured 'unwanted-reply-threshold' that triggers a defensive cache clear. A malicious actor who controls a delegation that returns in-bailiwick glue of 0.0.0.0/::0 can drive the counter to the limit of 'unwanted-reply-threshold' to the threshold and trigger a cache clean of the message and rrset caches; at will, indefinitely, without sending a single spoofed packet. The iterator uses the 0.0.0.0/::0 glue, and a system that can route this (e.g., Linux kernel routes the datagram over loopback), Unbound's own listener answers from 127.0.0.1. Because of the mismatch of 0.0.0.0 and 127.0.0.1, in this example, Unbound accounts the reply as an unwanted (probably spoofed) answer. The counter resets to zero on every cache flush, so the attack loops forever.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-50251"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-50251"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50251"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50251"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50251.txt"
        }
      ],
      "published": "2026-07-22T14:17:20+00:00",
      "updated": "2026-07-24T14:05:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-50252",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.3,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        349
      ],
      "description": "In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their outcome is revealed this secrecy is undermined. The vulnerability arises when the load balancing policy is consistent with respect to the incoming source UDP port and IP address while heavily depending on the incoming source UDP port as a randomization source. When the SO_REUSEPORT configuration option is enabled ('so-reuseport: yes') in Unbound (by default), it meets these conditions, making it vulnerable for DNS cache poisoning attacks. Upon startup, Unbound randomly partitions the available UDP source port space into disjoint subsets of (almost) equal size, assigning each subset to a specific worker thread. When an incoming DNS query is received, the kernel\u2019s SO_REUSEPORT load balancing mechanism deterministically assigns the query to a socket associated with a particular thread. All outgoing DNS queries generated during the resolution of that request use source ports selected exclusively from the port subset assigned to the corresponding thread. Since these port subsets are disjoint across threads, the source port observed in a resolver\u2019s outgoing query to an authoritative name server serves as a reliable indicator of the worker thread that processed the original client query. A malicious actor can acquire the mapping between incoming UDP source ports (for a given fixed source IP address) and Unbound worker threads and leverage it to conduct DNS cache poisoning attacks by effectively lowering the random port population per thread.",
      "recommendation": "Upgrade python3-unbound to version 1.16.2-5.14.el8_10.2; Upgrade unbound-libs to version 1.16.2-5.14.el8_10.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-50252"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:68292"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-50252"
        },
        {
          "url": "https://bugzilla.redhat.com/2506133"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506133"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-50252"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-68292.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:68292"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-50252.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69120.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50252"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50252"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50252.txt"
        }
      ],
      "published": "2026-07-22T14:17:20+00:00",
      "updated": "2026-07-24T14:05:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-50812",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-50812"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-50812"
        },
        {
          "url": "https://gist.github.com/junius-sec/bb556f333957c5226dede314db0e9e91"
        },
        {
          "url": "https://github.com/sqlite/sqlite/commit/b869ed6b067d623cb1383549f2a18aa35508385d"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50812"
        },
        {
          "url": "https://sqlite.org/src/info/e807d4e3798efd53"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8565-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50812"
        }
      ],
      "published": "2026-07-08T18:16:32+00:00",
      "updated": "2026-07-09T19:48:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.26.0-21.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/sqlite-libs@3.26.0-21.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-53613",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-53613"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-53613"
        },
        {
          "url": "https://github.com/util-linux/util-linux/security/advisories/GHSA-8gj5-72r3-428g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53613"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8702-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53613"
        }
      ],
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. This is a base-image OS utility vulnerability requiring local shell access and an admin-triggered mount race; not reachable through any CP product code path."
      }
    },
    {
      "id": "CVE-2026-53655",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N"
        }
      ],
      "cwes": [
        436
      ],
      "description": "node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata headers such as a GNU long-name (L) or long-link (K) entry. Per POSIX pax, a PAX extended header (x) describes the next file entry, not the intermediary extension headers that may sit between the x header and the file it annotates. Because node-tar lets the PAX size override the byte length of an intervening L/K/x header, an attacker can desynchronize node-tar's stream cursor relative to every other mainstream tar implementation (GNU tar, libarchive/bsdtar, Python tarfile, and the now-fixed tar-rs / astral-tokio-tar). The result is a tar parser interpretation differential (CWE-436): a single crafted archive yields a different set of members under node-tar than under the reference tar tools. An attacker can use this to hide a member from one parser while it is visible to another, which defeats security tooling whose scanner and extractor disagree on archive contents (e.g. a malware/secret scanner that lists entries with one library while a downstream step extracts with another) This vulnerability is fixed in 7.5.16.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-53655"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-53655"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-53655"
        },
        {
          "url": "https://github.com/advisories/GHSA-vmf3-w455-68vh"
        },
        {
          "url": "https://github.com/isaacs/node-tar"
        },
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-vmf3-w455-68vh"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53655"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53655"
        }
      ],
      "published": "2026-06-22T16:16:38+00:00",
      "updated": "2026-06-26T20:03:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-53910",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "diff3\u00a0tool from GNU diffutils\u00a0is vulnerable to a heap\u2011based buffer overflow due to multiple signed integer overflows in line\u2011mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds.\nWhen processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform out\u2011of\u2011bounds writes during internal processing.\u00a0\nAn attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment.\n\n\nThis issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815\u00a0\n\nNOTE:\nThe project maintainers claim that this is not a security issue. They state that the worst outcome this issue can cause is a crash of diff and that it cannot be used to escalate privileges.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-53910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-53910"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-53910"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=73ed7ce85cc78effb94daf028c9af6b4e5252e50"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=9ff04d5b84743e331e80b589335a52c5480d1815"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/diffutils.git/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53910"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8692-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53910"
        }
      ],
      "published": "2026-07-22T14:17:21+00:00",
      "updated": "2026-07-27T12:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6-6.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-5419",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        208
      ],
      "description": "A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5419"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13274"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20612"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20613"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26409"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29197"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30004"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:32962"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72502"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74674"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5419"
        },
        {
          "url": "https://bugzilla.redhat.com/2445763"
        },
        {
          "url": "https://bugzilla.redhat.com/2450624"
        },
        {
          "url": "https://bugzilla.redhat.com/2450625"
        },
        {
          "url": "https://bugzilla.redhat.com/2467279"
        },
        {
          "url": "https://bugzilla.redhat.com/2467289"
        },
        {
          "url": "https://bugzilla.redhat.com/2467437"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445762"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450624"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450625"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467279"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467289"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467437"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467441"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467451"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467678"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467686"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33845"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33846"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3832"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3833"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42009"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42015"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5260"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5419"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-20612.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:20612"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-5419.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50346.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5419"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8284-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5419"
        },
        {
          "url": "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-13"
        }
      ],
      "published": "2026-06-01T21:16:47+00:00",
      "updated": "2026-10-02T03:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.16-8.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-54872",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        208
      ],
      "description": "Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54872"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54872"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54872"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54872"
        }
      ],
      "published": "2026-09-29T16:17:08+00:00",
      "updated": "2026-10-08T01:19:04+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-54873",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54873"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54873"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54873"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8861-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54873"
        }
      ],
      "published": "2026-09-29T16:17:08+00:00",
      "updated": "2026-10-08T01:19:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-54874",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        405
      ],
      "description": "Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54874"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54874"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54874.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54874"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8865-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54874"
        }
      ],
      "published": "2026-08-25T13:19:24+00:00",
      "updated": "2026-09-11T21:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-54875",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        208
      ],
      "description": "Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54875"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54875"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54875"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54875"
        }
      ],
      "published": "2026-09-29T16:17:08+00:00",
      "updated": "2026-10-08T01:19:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-5545",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        305,
        613
      ],
      "description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1...",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5545"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5545"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5545.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5545.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-6g7g-56fm-f8mp"
        },
        {
          "url": "https://hackerone.com/reports/3642555"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5545"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5545"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-09-15T07:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-55708",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        1188
      ],
      "description": "In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost). Once the local zone tree exists without the defaults, every query for a default-protected name from a client mapped to that view escapes to the public DNS via the iterator instead of being answered locally, bypassing local policy expectations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55708"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55708"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55708"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55708"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-55708.txt"
        }
      ],
      "published": "2026-07-22T14:17:21+00:00",
      "updated": "2026-07-24T14:24:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-55717",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: <net> redirect' /'response-ip-data: <net> CNAME <target>' rule (or the RPZ 'rpz-cname-override' equivalent), a remote client who controls any delegated domain can crash the daemon. The serve-expired-client-timeout callback runs a two-pass loop to chase the respip-generated CNAME alias; on the second pass it resets 'alias_rrset' but not 'partial_rep'. Later, this inconsistency leads to a NULL pointer dereference and an eventual crash. A malicious actor can exploit the vulnerability by controlling any zone that replies with an A/AAAA record that falls inside the configured response-ip/rpz subnet. By delaying the answer when the previous record has expired, the vulnerable path of 'serve-expired-client-timeout' is taken leading to denial of service via the server crash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55717"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55717"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55717"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55717"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-55717.txt"
        }
      ],
      "published": "2026-07-22T14:17:21+00:00",
      "updated": "2026-07-24T14:24:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-55990",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        457
      ],
      "description": "In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' bytes. Any unauthenticated client that sends one UDP datagram of \u2265 68 bytes whose first 8 bytes are '0xdb' to 'dnscrypt-port' will use that garbage entry which leads to a garbage dereference killing the server. This is a silent faulty configuration that goes unnoticed until triggered with the right client query. Unbound needs to be compiled with DNSCrypt support ('--enable-dnscrypt').",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55990"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55990"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55990"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55990"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-55990.txt"
        }
      ],
      "published": "2026-07-22T14:17:21+00:00",
      "updated": "2026-07-24T14:24:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56109",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        415
      ],
      "description": "The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_def() fails to check return values before continuing, causing snd_config_delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56109"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56109"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/commit/536dd6f8affdf5197c12a63a71c92a70b2833cc0"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/releases/tag/v1.2.16.1"
        },
        {
          "url": "https://lore.kernel.org/alsa-devel/CAGt8pqBU0p2voB+qHxWGcNJrKHAcBhAyHUUBPLBN-Yj_SiV6MQ@mail.gmail.com/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56109"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8538-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56109"
        },
        {
          "url": "https://www.vulncheck.com/advisories/alsa-library-double-free-via-parse-def-in-conf-c"
        }
      ],
      "published": "2026-06-22T18:16:48+00:00",
      "updated": "2026-07-14T22:17:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.2.10-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56131",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56131"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56131"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1267"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56131"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8813-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56131"
        }
      ],
      "published": "2026-06-19T06:17:10+00:00",
      "updated": "2026-06-23T20:15:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56391",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "GNU coreutils uniq is vulnerable to an out\u2011of\u2011bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56391"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67886"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56391"
        },
        {
          "url": "https://bugzilla.redhat.com/2506691"
        },
        {
          "url": "https://bugzilla.redhat.com/2506694"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506694"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-56391"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56391"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56392"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-67886.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67886"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"
        },
        {
          "url": "https://github.com/advisories/GHSA-7xvj-m9x7-qgxq"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56391.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67886.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56391"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8697-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56391"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/25/2"
        }
      ],
      "published": "2026-07-24T09:16:25+00:00",
      "updated": "2026-08-26T13:52:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.30-20.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/coreutils-single@8.30-20.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56403",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in storeAtts.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56403"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56403"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1232"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56403"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8790-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56403"
        }
      ],
      "published": "2026-06-21T16:16:26+00:00",
      "updated": "2026-06-23T20:15:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56404",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in addBinding.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56404"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56404"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1249"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56404"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8790-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8872-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56404"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T20:15:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56405",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in getAttributeId.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56405"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56405"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1251"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56405"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8790-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8872-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56405"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T20:14:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56406",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56406"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56406"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1255"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56406"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8813-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56406"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T16:29:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56407",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56407"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56407"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1262"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56407"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8813-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56407"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T16:28:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56412",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56412"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56412"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1278"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56412"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8790-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56412"
        }
      ],
      "published": "2026-06-21T17:16:44+00:00",
      "updated": "2026-06-23T15:31:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56416",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "cwes": [
        354
      ],
      "description": "In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker who runs a DNSSEC-signed authoritative server can deliver a record with an absent second domain name (e.g. SOA record) and cause 'query_dname_tolower()' to walk label-by-label through stale bytes in the per-worker 'env->scratch_buffer', past the end of that heap allocation if 'msg-buffer-size' has been lowered from the default. This leads to heap buffer overflow and on a release build the outcome relies heavily on the contents of the buffer tail and the adjacent heap chunk.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56416"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56416"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56416"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56416"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-56416.txt"
        }
      ],
      "published": "2026-07-22T14:17:22+00:00",
      "updated": "2026-07-24T14:25:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-5704",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        434
      ],
      "description": "A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.",
      "recommendation": "Upgrade tar to version 2:1.30-13.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5704"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/11/10"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/11/11"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/12/2"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61581"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61586"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61783"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66514"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70390"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5704"
        },
        {
          "url": "https://bugzilla.redhat.com/2455360"
        },
        {
          "url": "https://bugzilla.redhat.com/2509735"
        },
        {
          "url": "https://bugzilla.redhat.com/2509843"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455360"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509735"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509843"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18477"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18508"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5704"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-61581.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:61581"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-5704.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70390.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5704"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8477-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8477-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8477-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5704"
        }
      ],
      "published": "2026-04-06T16:16:42+00:00",
      "updated": "2026-09-22T22:17:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-57062",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        1284
      ],
      "description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-57062"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-57062"
        },
        {
          "url": "https://blog.calif.io/p/how-to-format-a-ciphertext"
        },
        {
          "url": "https://github.com/advisories/GHSA-m6x2-4hhh-669j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57062"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8720-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-57062"
        },
        {
          "url": "https://www.gnupg.org/download"
        },
        {
          "url": "https://www.gnupg.org/download/"
        }
      ],
      "published": "2026-06-23T18:18:10+00:00",
      "updated": "2026-06-25T20:16:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.2.20-4.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5713",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121,
        125
      ],
      "description": "The \"profiling.sampling\" module (Python 3.15+) and \"asyncio introspection capabilities\" (3.14+, \"python -m asyncio ps\" and \"python -m asyncio pstree\") features could be used to read and write addresses in a privileged process if that process connected to a malicious or \"infected\" Python process via the remote debugging feature. This vulnerability requires persistently and repeatedly connecting to the process to be exploited, even after the connecting process crashes with high likelihood due to ASLR.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5713"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/15/6"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19176"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5713"
        },
        {
          "url": "https://bugzilla.redhat.com/2431367"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/2458239"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458239"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0865"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5713"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19176.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19176"
        },
        {
          "url": "https://github.com/python/cpython/commit/289fd2c97a7e5aecb8b69f94f5e838ccfeee7e67"
        },
        {
          "url": "https://github.com/python/cpython/commit/316f6265b7f9ca4ffed5346b747475ef1943f35d"
        },
        {
          "url": "https://github.com/python/cpython/issues/148178"
        },
        {
          "url": "https://github.com/python/cpython/pull/148187"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-5713.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19176.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/OG4RHARYSNIE22GGOMVMCRH76L5HKPLM/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5713"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5713"
        }
      ],
      "published": "2026-04-14T16:16:48+00:00",
      "updated": "2026-07-31T14:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5745",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare \"d\" or \"default\" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5745"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8944"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5745"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455921"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5745"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8581-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5745"
        }
      ],
      "published": "2026-04-07T16:16:32+00:00",
      "updated": "2026-09-01T12:17:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5773",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        488,
        918
      ],
      "description": "libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different \"share\" than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5773"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5773"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5773.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5773.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-rp9q-8q5w-ch44"
        },
        {
          "url": "https://hackerone.com/reports/3650689"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5773"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5773"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-09-15T07:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58058",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        191
      ],
      "description": "Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash during raw IPv6 scans.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58058"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58058"
        },
        {
          "url": "https://github.com/bikini/exploitarium/tree/main/nmap-ipv6-extlen-wrap-poc"
        },
        {
          "url": "https://github.com/nmap/nmap/commit/bb6754e76bb1686315008e1aa1c40202a513fb83"
        },
        {
          "url": "https://nmap.org/changelog.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58058"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58058"
        },
        {
          "url": "https://www.vulncheck.com/advisories/nmap-integer-underflow-in-ipv6-extension-header-parsing"
        }
      ],
      "published": "2026-06-28T02:16:33+00:00",
      "updated": "2026-06-30T17:31:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:7.92-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58470",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58470"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58470"
        },
        {
          "url": "https://github.com/advisories/GHSA-5f52-px6m-c5hw"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58470"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58470"
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-integer-overflow-via-content-range-header-parsing"
        }
      ],
      "published": "2026-07-07T21:17:28+00:00",
      "updated": "2026-07-09T16:01:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.19.5-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/wget@1.19.5-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5958",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        367
      ],
      "description": "When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations on the same path: \n1. resolves symlink to its target and stores\u00a0the resolved path for determining when output is written,\n2. opens the original symlink path\u00a0(not the resolved one) to read the file. \nBetween these two calls there is a race window. If an attacker atomically replaces the symlink with a different target during that window, sed will: read content from the new (attacker-chosen) symlink target and write the processed result to the path recorded in step 1.\u00a0This can lead to arbitrary file overwrite with attacker-controlled content in the context of the sed process.\n\n\nThis issue was fixed in version 4.10.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5958"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/13/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5958"
        },
        {
          "url": "https://cert.pl/en/posts/2026/04/CVE-2026-5958"
        },
        {
          "url": "https://github.com/advisories/GHSA-9r7w-j29g-xqx8"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5958"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8229-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8229-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5958"
        },
        {
          "url": "https://www.gnu.org/software/sed"
        },
        {
          "url": "https://www.gnu.org/software/sed/"
        }
      ],
      "published": "2026-04-20T12:16:08+00:00",
      "updated": "2026-06-17T10:59:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.5-5.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-59890",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        }
      ],
      "cwes": [
        176,
        697
      ],
      "description": "setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.",
      "recommendation": "Upgrade setuptools to version 83.0.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59890"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59890"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-59890"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2026-3447.yaml"
        },
        {
          "url": "https://github.com/pypa/setuptools"
        },
        {
          "url": "https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f"
        },
        {
          "url": "https://github.com/pypa/setuptools/releases/tag/v83.0.0"
        },
        {
          "url": "https://github.com/pypa/setuptools/security/advisories/GHSA-h35f-9h28-mq5c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59890"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59890"
        }
      ],
      "published": "2026-07-08T17:17:27+00:00",
      "updated": "2026-07-13T17:04:58+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@70.3.0",
          "versions": [
            {
              "version": "70.3.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:pypi/setuptools@70.3.0"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:pypi/setuptools@70.3.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. This is a build-time-only sdist-packaging bug requiring a non-default macOS filesystem; CP never builds sdists from untrusted input."
      }
    },
    {
      "id": "CVE-2026-6019",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        150,
        116
      ],
      "description": "http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28247"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6019"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/2460869"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460869"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6019"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-28247.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28247"
        },
        {
          "url": "https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c"
        },
        {
          "url": "https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104"
        },
        {
          "url": "https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8"
        },
        {
          "url": "https://github.com/python/cpython/issues/90309"
        },
        {
          "url": "https://github.com/python/cpython/pull/148848"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-6019.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-28581.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6019"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8744-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6019"
        }
      ],
      "published": "2026-04-22T20:16:42+00:00",
      "updated": "2026-07-27T17:34:54+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6244",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        369
      ],
      "description": "libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero.  In particular uncommon use cases a crafted filter program can cause a division by zero.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6244"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6244"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6244"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6244"
        }
      ],
      "published": "2026-09-05T19:16:55+00:00",
      "updated": "2026-09-08T19:20:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14",
          "versions": [
            {
              "version": "14:1.9.1-5.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-6253",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        522
      ],
      "description": "curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6253"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/11"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6253"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6253.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6253.json"
        },
        {
          "url": "https://hackerone.com/reports/3669637"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6253"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6253"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-09-15T07:16:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6276",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        346,
        319
      ],
      "description": "Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6276"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/13"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6276"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6276.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6276.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-2jc6-hc33-hv48"
        },
        {
          "url": "https://hackerone.com/reports/3671818"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6276"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6276"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-09-15T07:16:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-63072",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63072"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63072"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63072.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63072"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8865-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63072"
        }
      ],
      "published": "2026-08-25T13:19:26+00:00",
      "updated": "2026-09-11T21:16:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63379",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in http.c through evhttp_read_trailer and merges them into request headers. The fix introduces evhttp_parse_headers_impl_ and a temporary trailer header list. An unauthenticated remote attacker can place security-sensitive fields in trailers so that an upstream proxy and the libevent application interpret different effective headers, enabling header smuggling, authorization bypass, proxy-header spoofing, or cache poisoning. The fix parses trailers into a temporary header list and discards them instead of merging them into req->input_headers. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63379"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63379"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/87e8e44fa774e9677b089b1a5114ee68aefa1636"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/b847071141b3827900d536594ec9045eb0a4c485"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-2gmv-p5m7-98p6"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63379.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63379"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63379"
        }
      ],
      "published": "2026-08-20T18:16:35+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.1.8-5.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63380",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        416,
        476
      ],
      "description": "Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters its error path after evhttp_start_ws_ succeeds but bufferevent_enable_locking_ fails. evws_connection_free sees a non-null http_server and unconditionally calls TAILQ_REMOVE even though the session was never inserted into http_server->ws_sessions. A local caller able to induce this allocation or locking failure can crash the process. This issue is fixed in version 2.2.2-alpha.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63380"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63380"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/825c18bd99f556b59d61200523237f264d5cc734"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-3rpf-frgx-xq34"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63380"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63380"
        }
      ],
      "published": "2026-08-20T18:16:35+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.1.8-5.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-63381",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        908
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains frees the initial empty chain without resetting outbuf->first, outbuf->last, or outbuf->last_with_datap, and APPEND_CHAIN_MULTICAST subsequently dereferences the dangling chain pointer. A caller that can drive this buffer state can cause memory corruption or a process crash. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63381"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63381"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/5cb95ba2f804f8aff46f88d58391c71e1251cd1c"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/9db091b04f569be3a700fa9860ef02f90b830af9"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-c2pj-cg4r-88c8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63381.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63381"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8710-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63381"
        }
      ],
      "published": "2026-08-20T18:16:35+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.1.8-5.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63382",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-Encoding values, and bare line feeds in chunked framing. evhttp_find_header can select only the first header, evhttp_check_transfer_encoding_ was absent so the previous whole-string comparison fails to recognize valid lists ending in chunked, and evhttp_handle_chunked_read uses EVBUFFER_EOL_CRLF rather than EVBUFFER_EOL_CRLF_STRICT, accepting bare LF chunk terminators. When libevent is deployed behind a proxy that frames the same request differently, an unauthenticated remote attacker can desynchronize request boundaries and smuggle a second request, potentially bypassing access controls or poisoning caches. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "recommendation": "Upgrade libevent to version 2.1.8-11.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63382"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63382"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/10abb34b8dc3e1184de315dd261ce4b77563cda6"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/5119ceb00557bf007f9065709e852686f3c0bb6e"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/83ba67373032334559b82409db035dd8c3cc1660"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/ac38703b2d312200c4f967f02936af0118d384a0"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-q39v-w2g7-gr8j"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63382.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63382"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8710-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63382"
        }
      ],
      "published": "2026-08-20T18:16:35+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.1.8-5.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63383",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c when decode_tag_internal requests at most five bytes from evbuffer_pullup but iterates using the full logical buffer length. A fragmented evbuffer containing a six-byte malformed tag can therefore advance past the pullup window and trigger an out-of-bounds read, which can crash a process that decodes attacker-controlled tagged RPC data. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "recommendation": "Upgrade libevent to version 2.1.8-11.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63383"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63383"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/91ed8745eebabdd27592a83d350338a8c4626321"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/e1f9e21887c6b104e206a718385ba3ffc75180cb"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-fj29-64w6-73h6"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63383.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63383"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8710-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63383"
        }
      ],
      "published": "2026-08-20T18:16:35+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.1.8-5.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63384",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode an attacker-controlled uint32 payload length and returns it as a signed int. Values above INT_MAX become negative or truncated, and evtag_unmarshal_string can use the converted value in allocation sizing, producing a wrapped large allocation request and denial of service. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "recommendation": "Upgrade libevent to version 2.1.8-11.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63384"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63384"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/109c16499282959d70f56ec3baf4c8b1e6646bda"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/5e3c6ebe342b34c5a9bcf48e9a32ad6708b9c416"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-45c6-qx49-89m8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63384.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63384"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8710-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63384"
        }
      ],
      "published": "2026-08-20T18:16:36+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.1.8-5.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63385",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into literal NUL characters, which can cause downstream C string operations to truncate a path and bypass validation performed on a different representation. evhttp_header_is_valid_value also accepts obsolete line folding in header values containing carriage return or line feed characters, allowing a proxy and libevent to interpret headers differently and enabling header injection or access control bypass. The CRLF header acceptance is fixed in versions 2.1.13 and 2.2.2-alpha, but the reviewed patches do not clearly remediate the URI NUL-truncation condition.",
      "recommendation": "Upgrade libevent to version 2.1.8-11.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63385"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63385"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/758be0c0f69c1934ef9a84ab39e9f9e5fde2e6d0"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/9170dd35e64714613e8d13b290587cfc28e258e2"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-jcwh-pvf2-73p2"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63385.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63385"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8710-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63385"
        }
      ],
      "published": "2026-08-20T18:16:36+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.1.8-5.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63387",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.6,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121,
        193,
        787
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocated by evdns_server_request_format_response. The final-label check permits j plus label_len plus one to equal buf_len, after which the terminating null byte is written to buf[buf_len]. A crafted DNS server response containing PTR, CNAME, MX, NS, or SOA data can trigger the one-byte out-of-bounds write and crash or corrupt the process. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "recommendation": "Upgrade libevent to version 2.1.8-11.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63387"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-58rx-7448-jw47"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63387.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63387"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8840-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63387"
        }
      ],
      "published": "2026-08-20T18:16:36+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.1.8-5.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63388",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        617,
        787
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when bufferevent_socket_set_conn_address_ copies a kernel-supplied AF_UNIX peer address into bufferevent_private.conn_address. Release builds compiled with NDEBUG disable the EVUTIL_ASSERT length guard, and the evhttp accept path can pass a 110-byte sockaddr from accept() into the 28-byte field. An unauthenticated local peer able to connect to an AF_UNIX listener can overwrite the adjacent dns_request pointer and heap data, causing memory corruption with confidentiality, integrity, and availability impact. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "recommendation": "Upgrade libevent to version 2.1.8-11.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63388"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63388"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-cvq5-vrvr-j338"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63388.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63388"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8840-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63388"
        }
      ],
      "published": "2026-08-20T18:16:36+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.1.8-5.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libevent@2.1.8-5.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-6368",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        908
      ],
      "description": "Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43\u00a0can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.",
      "recommendation": "Upgrade glibc to version 2.28-251.el8_10.43; Upgrade glibc-common to version 2.28-251.el8_10.43; Upgrade glibc-minimal-langpack to version 2.28-251.el8_10.43",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6368"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76777"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6368"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2513603"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2513608"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6368"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6791"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-76777.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:76777"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6368"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34090"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6368"
        }
      ],
      "published": "2026-08-10T19:17:30+00:00",
      "updated": "2026-09-03T16:43:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-6429",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        200
      ],
      "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6429"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6429"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6429.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6429.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-2pvc-5qw9-h3ph"
        },
        {
          "url": "https://hackerone.com/reports/3677759"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6429"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6429"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-09-15T07:16:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6554",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        835
      ],
      "description": "libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does not limit the number of loop iterations.  In particular uncommon use cases a crafted filter program can cause the interpreter to loop infinitely.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6554"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6554"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/ff3c83475ac303c6b681c52ad0b6e14795a8e0ce"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6554"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6554"
        }
      ],
      "published": "2026-09-05T19:16:56+00:00",
      "updated": "2026-09-08T19:20:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14",
          "versions": [
            {
              "version": "14:1.9.1-5.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-66046",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        407
      ],
      "description": "Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.",
      "recommendation": "Upgrade expat to version 2.5.0-4.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-66046"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72663"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-66046"
        },
        {
          "url": "https://bugzilla.redhat.com/2538967"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517901"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2538967"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-66046"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-93990"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-72663.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:72663"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1321"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-66046.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-74001.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66046"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8813-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-66046"
        },
        {
          "url": "https://www.vulncheck.com/advisories/expat-denial-of-service-via-storeatts-quadratic-complexity"
        }
      ],
      "published": "2026-08-18T15:16:57+00:00",
      "updated": "2026-09-18T15:07:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-6653",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416,
        611
      ],
      "description": "Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.",
      "recommendation": "Upgrade libxml2 to version 2.9.7-21.el8_10.8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6653"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61247"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6653"
        },
        {
          "url": "https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260"
        },
        {
          "url": "https://bugzilla.redhat.com/2491354"
        },
        {
          "url": "https://bugzilla.redhat.com/2494191"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491354"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494191"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11979"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6653"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-61247.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:61247"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-6653.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69655.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6653"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8456-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6653"
        }
      ],
      "published": "2026-06-22T14:17:51+00:00",
      "updated": "2026-07-14T16:00:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-67693",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "description": "An issue in gnutls v.3.8.13 allows an attacker to obtain sensitive information via failing to reject end-entity X.509 certificates that contain a contradictory combination of Key Usage (KU) and Extended Key Usage (EKU)",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-67693"
        },
        {
          "url": "http://gnutls.com"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-67693"
        },
        {
          "url": "https://gist.github.com/lkloliver/6fbfc191bc6163942c8017551ac3f238"
        },
        {
          "url": "https://gitlab.com/gnutls/gnutls/-/blob/3.8.13/lib/x509/verify.c#L1119-1178"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67693"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-67693"
        }
      ],
      "published": "2026-10-08T19:18:41+00:00",
      "updated": "2026-10-08T21:33:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.16-8.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ]
    },
    {
      "id": "CVE-2026-6791",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
      "recommendation": "Upgrade glibc to version 2.28-251.el8_10.43; Upgrade glibc-common to version 2.28-251.el8_10.43; Upgrade glibc-minimal-langpack to version 2.28-251.el8_10.43",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6791"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76777"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6791"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2513603"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2513608"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6368"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6791"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-76777.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:76777"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6791"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34091"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0013"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6791"
        }
      ],
      "published": "2026-08-10T19:17:30+00:00",
      "updated": "2026-09-03T16:43:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-7168",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        294
      ],
      "description": "Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-7168"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/14"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-7168"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-7168.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-7168.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-v92m-hrhj-gw54"
        },
        {
          "url": "https://hackerone.com/reports/3697719"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7168"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7168"
        }
      ],
      "published": "2026-05-13T13:01:57+00:00",
      "updated": "2026-09-15T07:16:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-7210",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        331
      ],
      "description": "`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-7210"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/11/13"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/11/8"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-7210"
        },
        {
          "url": "https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4"
        },
        {
          "url": "https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566"
        },
        {
          "url": "https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56"
        },
        {
          "url": "https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b"
        },
        {
          "url": "https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286"
        },
        {
          "url": "https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a"
        },
        {
          "url": "https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f"
        },
        {
          "url": "https://github.com/python/cpython/issues/149018"
        },
        {
          "url": "https://github.com/python/cpython/pull/149023"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7210"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7210"
        }
      ],
      "published": "2026-05-11T18:16:42+00:00",
      "updated": "2026-10-02T01:16:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-72712",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        835
      ],
      "description": "Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in nselib/packet.lua to allocate objects in an infinite loop, causing an out-of-memory condition that results in application crash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-72712"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-72712"
        },
        {
          "url": "https://github.com/nmap/nmap"
        },
        {
          "url": "https://github.com/nmap/nmap/commit/7ef4ee030a0023fe22616387a000032e1a678b6a"
        },
        {
          "url": "https://github.com/nmap/nmap/issues/3368"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72712"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72712"
        },
        {
          "url": "https://www.vulncheck.com/advisories/nmap-denial-of-service-via-zero-length-tcp-option-packet"
        }
      ],
      "published": "2026-08-11T18:18:23+00:00",
      "updated": "2026-09-24T20:30:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:7.92-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-72897",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-72897"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-72897"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72897"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72897"
        }
      ],
      "published": "2026-09-29T16:17:09+00:00",
      "updated": "2026-10-08T01:19:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-7383",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: A signed integer overflow when sizing the destination\nbuffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap\nbuffer overflow.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nattacker controlled code execution or other undefined behaviour.\n\nIn ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination\nsize for Unicode output is computed in a signed int: by left shift\nof the input character count for BMPSTRING (UTF-16) and\nUNIVERSALSTRING (UTF-32), and by summing per-character byte counts\nfor UTF8STRING. The calculation overflows when the input reaches\naround 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30\ncharacters) the size wraps to zero, OPENSSL_malloc(1) is called, and\nthe subsequent character copy writes several gigabytes past the\none-byte allocation.\n\nX.509 certificate processing routes through ASN1_STRING_set_by_NID(),\nwhose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID\nsize limits cap the input length; no network protocol or\ncertificate-handling path in OpenSSL exercises the overflow.\nTriggering the bug requires an application that calls\nASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers\na custom string type via ASN1_STRING_TABLE_add(), with\nattacker-controlled input on the order of half a gigabyte or more.\nFor these reasons this issue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as the affected code is outside the OpenSSL FIPS module\nboundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-7383"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-7383"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-w853-v86g-gv7j"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/80c15faaf78042bbb8654a0e234c50c381732f74"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bd17511070fb39a67bfa19682affb765e706a974"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/c332adaced43bcbb85f97410597e951c11ec3083"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255"
        },
        {
          "url": "https://github.com/openssl/security/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6"
        },
        {
          "url": "https://github.com/openssl/security/commit/80c15faaf78042bbb8654a0e234c50c381732f74"
        },
        {
          "url": "https://github.com/openssl/security/commit/bd17511070fb39a67bfa19682affb765e706a974"
        },
        {
          "url": "https://github.com/openssl/security/commit/c332adaced43bcbb85f97410597e951c11ec3083"
        },
        {
          "url": "https://github.com/openssl/security/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-7383.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7383"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7383"
        }
      ],
      "published": "2026-06-09T17:17:50+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-74860",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        763
      ],
      "description": "A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.",
      "recommendation": "Upgrade libxml2 to version 2.9.7-21.el8_10.9",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-74860"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:64463"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71585"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71586"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71641"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:79357"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-74860"
        },
        {
          "url": "https://bugzilla.redhat.com/2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/2529697"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529697"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86140"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86142"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86143"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86144"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71585.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71585"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-74860.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-74860"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8787-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74860"
        }
      ],
      "published": "2026-09-08T12:16:58+00:00",
      "updated": "2026-10-09T02:17:04+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-75806",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        1284
      ],
      "description": "Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-75806"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-75806"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75806"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75806"
        }
      ],
      "published": "2026-09-29T16:17:11+00:00",
      "updated": "2026-10-08T01:20:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-76641",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to read the attIndex member past allocated memory boundaries, resulting in failure to normalize whitespace in non-CDATA attributes or a wild pointer dereference causing a segfault. This vulnerability was introduced by the fix for CVE-2026-66046.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-76641"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-76641"
        },
        {
          "url": "https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1331"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76641"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8813-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-76641"
        },
        {
          "url": "https://www.vulncheck.com/advisories/expat-out-of-bounds-read-via-dtdcopy"
        }
      ],
      "published": "2026-08-20T18:16:51+00:00",
      "updated": "2026-09-24T20:02:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-76781",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-76781"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57604"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-76781"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2519776"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/commit/c6324894"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/442"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76781"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8910-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-76781"
        }
      ],
      "published": "2026-09-17T16:17:42+00:00",
      "updated": "2026-09-24T12:17:12+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-76957",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-76957"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-76957"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1322"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1329"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76957"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8813-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-76957"
        }
      ],
      "published": "2026-08-20T05:16:29+00:00",
      "updated": "2026-09-08T20:56:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-77117",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        835
      ],
      "description": "Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-77117"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-77117"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77117"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34556"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77117"
        }
      ],
      "published": "2026-09-15T11:17:12+00:00",
      "updated": "2026-09-18T18:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-77214",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L"
        }
      ],
      "cwes": [
        125
      ],
      "description": "libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-77214"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-77214"
        },
        {
          "url": "https://github.com/libexpat/libexpat/commit/13c5f63a7f1c52c2feee3b16a1134d4fb68e9ea0"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1393"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77214"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77214"
        },
        {
          "url": "https://www.vulncheck.com/advisories/libexpat-heap-buffer-over-read-in-xmlparse-c-via-xml-parsebuffer"
        }
      ],
      "published": "2026-10-07T15:17:53+00:00",
      "updated": "2026-10-07T15:57:20+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-77696",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        208
      ],
      "description": "Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-77696"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-77696"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77696"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77696"
        }
      ],
      "published": "2026-09-29T16:17:11+00:00",
      "updated": "2026-10-08T01:20:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-7774",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        22
      ],
      "description": "tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-7774"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/06/04/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-7774"
        },
        {
          "url": "https://github.com/python/cpython/commit/0478bd83d82b255e0f29f613367a59d261e7eaa2"
        },
        {
          "url": "https://github.com/python/cpython/commit/0d28f5e46e151718972dfabd91205444d0037b6d"
        },
        {
          "url": "https://github.com/python/cpython/commit/10a13bee3c24f9c62b602e696334ff2272a40efc"
        },
        {
          "url": "https://github.com/python/cpython/commit/578411982c16f753f4893532510099ef665117da"
        },
        {
          "url": "https://github.com/python/cpython/commit/5cf47a248c35c375d610b87b2f72fd1ed454b558"
        },
        {
          "url": "https://github.com/python/cpython/commit/74cca9a92fb7d653e404843a56b8bdc7b0afdbbf"
        },
        {
          "url": "https://github.com/python/cpython/commit/c063191cb7f9170f9565e305f8aa2b79ab2bf609"
        },
        {
          "url": "https://github.com/python/cpython/issues/149486"
        },
        {
          "url": "https://github.com/python/cpython/pull/149487"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/4FU62L2M6RMMHT2QPGQNPEHHUND7CEX5/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7774"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7774"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/06/04/9"
        }
      ],
      "published": "2026-06-04T16:16:42+00:00",
      "updated": "2026-08-13T01:16:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-78.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/platform-python@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-libs@3.6.8-78.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-77955",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        345
      ],
      "description": "In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchronous resolution that needs to happen before the ZONEMD check completes. If a zonefile is written to disk (zonefile: option) while the ZONEMD check failed, the tampered data are reloaded on startup and available until ZONEMD verification concludes again. If verification fails, the data is not served any more but still persists on disk for future reloads.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-77955"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-77955"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77955"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77955"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-77955.txt"
        }
      ],
      "published": "2026-09-16T09:17:05+00:00",
      "updated": "2026-09-23T20:19:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-78367",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        94
      ],
      "description": "A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78367"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-78367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2521857"
        },
        {
          "url": "https://github.com/rpm-software-management/rpm/issues/4314"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78367"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78367"
        }
      ],
      "published": "2026-08-24T14:17:04+00:00",
      "updated": "2026-09-04T12:17:19+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The vulnerable rpmbuild tarball-mode code path is never invoked by CP; rpm/python3-rpm are base-image package-manager components only."
      }
    },
    {
      "id": "CVE-2026-80225",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        770
      ],
      "description": "In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of distinct uncached names over the TCP/DoT connection, monopolizes a single worker's entire event loop for as long as its writes stay ahead of the drain.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-80225"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-80225"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80225"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-80225"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-80225.txt"
        }
      ],
      "published": "2026-09-16T09:17:06+00:00",
      "updated": "2026-09-23T19:57:08+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-80230",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        295
      ],
      "description": "When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-80230"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-80230"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-80230.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-80230.json"
        },
        {
          "url": "https://github.com/curl/curl/commit/5267ed859d545534d0c21"
        },
        {
          "url": "https://hackerone.com/reports/3969300"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80230"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8820-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-80230"
        }
      ],
      "published": "2026-09-06T18:17:22+00:00",
      "updated": "2026-09-15T07:16:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-80489",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        835
      ],
      "description": "Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-80489"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-80489"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80489"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34568"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-80489"
        }
      ],
      "published": "2026-09-15T11:17:12+00:00",
      "updated": "2026-09-18T18:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-81634",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "critical"
        }
      ],
      "cwes": [
        122
      ],
      "description": "In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor operating a malicious name server or tampering with an incoming response to Unbound (canonicalisation happens before DNSSEC validation), can trigger the vulnerability.",
      "recommendation": "Upgrade python3-unbound to version 1.16.2-5.14.el8_10.4; Upgrade unbound-libs to version 1.16.2-5.14.el8_10.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-81634"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71487"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-81634"
        },
        {
          "url": "https://bugzilla.redhat.com/2535051"
        },
        {
          "url": "https://bugzilla.redhat.com/2535054"
        },
        {
          "url": "https://bugzilla.redhat.com/2535059"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2535051"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2535054"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2535059"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-81634"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-81642"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-82717"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71487.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71487"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-81634.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71487.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81634"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-81634"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-81634.txt"
        }
      ],
      "published": "2026-09-16T09:17:06+00:00",
      "updated": "2026-09-23T19:51:14+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-81642",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerability by controlling a malicious zone and querying a vulnerable Unbound.",
      "recommendation": "Upgrade python3-unbound to version 1.16.2-5.14.el8_10.4; Upgrade unbound-libs to version 1.16.2-5.14.el8_10.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-81642"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71487"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-81642"
        },
        {
          "url": "https://bugzilla.redhat.com/2535051"
        },
        {
          "url": "https://bugzilla.redhat.com/2535054"
        },
        {
          "url": "https://bugzilla.redhat.com/2535059"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2535051"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2535054"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2535059"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-81634"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-81642"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-82717"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71487.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71487"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-81642.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71487.html"
        },
        {
          "url": "https://nlnetlabs.nl/downloads/unbound/CVE-2026-81642.txt"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81642"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8873-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-81642"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-81642.txt"
        }
      ],
      "published": "2026-09-16T09:17:06+00:00",
      "updated": "2026-09-22T18:59:21+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-82209",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        201
      ],
      "description": "When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-82209"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-82209"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-82209.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-82209.json"
        },
        {
          "url": "https://github.com/curl/curl/commit/95c1e8915dce64606bd753fd47f"
        },
        {
          "url": "https://hackerone.com/reports/3972385"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82209"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8820-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-82209"
        }
      ],
      "published": "2026-09-06T18:17:22+00:00",
      "updated": "2026-09-15T07:16:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-82327",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        129
      ],
      "description": "A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's compressed filelist data without validating that they fall within the expected range. A corrupted or specially crafted .solv cache file (for example, one left in a torn state after an unclean system shutdown) can cause an out-of-bounds memory write when a tool such as dnf, yum, or zypper next processes it. Successful exploitation is expected to result in a crash of the affected tool (denial of service); it is not expected to allow arbitrary code execution because the out-of-bounds write always stores a fixed, non-attacker-controlled value.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-82327"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-82327"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2525602"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82327"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-82327"
        }
      ],
      "published": "2026-08-28T16:18:34+00:00",
      "updated": "2026-08-28T20:20:21+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.7.20-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-82717",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The vulnerability starts when CNAME synthesis during an upstream response needs to enforce(rewrite) a max TTL value in the packet buffer. Coupled with a compression pointer that points to the overwritten value and invalidates the domain name, it leads to an error path that does not properly move the buffer position and allows for the heap buffer overflow. Since this is heavily reliant on heap memory layout, results are memory corruption that eventually leads to a crash and under specific systems and compilation options remote code execution.",
      "recommendation": "Upgrade python3-unbound to version 1.16.2-5.14.el8_10.4; Upgrade unbound-libs to version 1.16.2-5.14.el8_10.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-82717"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71487"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-82717"
        },
        {
          "url": "https://bugzilla.redhat.com/2535051"
        },
        {
          "url": "https://bugzilla.redhat.com/2535054"
        },
        {
          "url": "https://bugzilla.redhat.com/2535059"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2535051"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2535054"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2535059"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-81634"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-81642"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-82717"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71487.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71487"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-82717.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71487.html"
        },
        {
          "url": "https://nlnetlabs.nl/downloads/unbound/CVE-2026-82717.txt"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82717"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8873-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-82717"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-82717.txt"
        }
      ],
      "published": "2026-09-16T09:17:06+00:00",
      "updated": "2026-09-23T19:50:17+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-8458",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        488
      ],
      "description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8458"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69126"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8458"
        },
        {
          "url": "https://bugzilla.redhat.com/2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/2496769"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496769"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8458.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8458.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8458.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8458"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8927"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-69126.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69126"
        },
        {
          "url": "https://github.com/advisories/GHSA-88c6-6jfq-mm4q"
        },
        {
          "url": "https://hackerone.com/reports/3721183"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8458.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69126.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8458"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8458"
        }
      ],
      "published": "2026-07-03T07:16:24+00:00",
      "updated": "2026-09-15T07:16:32+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-84782",
      "ratings": [
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-84782"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76918"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-84782"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2537080"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84782"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:76918"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-84782.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-77396.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84782"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://openssl-library.org/news/vulnerabilities/#CVE-2026-84782"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84782"
        }
      ],
      "published": "2026-09-29T16:17:12+00:00",
      "updated": "2026-10-08T01:20:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-84783",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "Issue summary: The first concurrent use of the same X.509 certificate by\nseveral threads may cause its cached extension data to be freed while\nanother thread is still using it.\n\nImpact summary: A remote, unauthenticated peer could crash a multi-threaded\nTLS client, or a multi-threaded TLS server that requests client\ncertificates, if the first certificate chains built to the same trusted CA\ncertificate are built by several connections at the same time. This is a\nuse-after-free read, which is likely to crash the process, resulting in a\nDenial of Service.\n\nCWE: CWE-416: Use After Free\n\nDescription: OpenSSL caches the decoded values of a certificate's X.509v3\nextensions inside the X509 object the first time they are needed. In\nOpenSSL 4.0 this cache is built in two phases: the extension values are\ncomputed while holding a read lock on the certificate, and the results are\nthen installed into the certificate under a write lock. Because a read lock\ndoes not exclude other readers, several threads can compute the cache for\nthe same certificate at the same time. Each thread that subsequently\nacquires the write lock installs its own results and frees the values\ninstalled by the thread before it, even though that earlier thread has\nalready marked the cache as complete and may have returned pointers into it\nto its caller. A caller still using those pointers then reads freed memory.\n\nAny certificate shared between threads is exposed the first time its\nextensions are decoded. In TLS the certificates at risk are the trusted CA\ncertificates supplied for chain verification, by whatever means, since these\nare shared by every connection and their extensions are decoded and cached\nthe first time a chain is built to them. Certificates sent by the peer are\ndecoded separately for each connection and are not shared, so they are not\naffected. In a TLS client verifying server certificates, or a TLS server\nthat requests and verifies client certificates, the use-after-free could\nonly occur if the first chains built to the same trusted CA are built by\nseveral connections at the same time.\n\nFIPS impact: no\nThe FIPS module is not affected as X.509 certificate handling is outside\nof the OpenSSL FIPS module boundary.\n\nOpenSSL 4.0 is vulnerable to this issue.\n\nOpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\n\nThis issue was reported on 27 August 2026 by Tim Becker (Xint.io) and\nindependently in a public report on 31 August 2026 by aydinmercan.\n\nThe fix has been developed by Bob Beck.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Tim Becker (Xint.io), aydinmercan\nFixed by: Bob Beck",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-84783"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-84783"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/de97a1a54f43edefd43b5084ecac54ecadb33081"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84783"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84783"
        }
      ],
      "published": "2026-09-29T16:17:12+00:00",
      "updated": "2026-10-08T01:21:13+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-84837",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        78
      ],
      "description": "A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-84837"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-84837"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2478408"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84837"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84837"
        }
      ],
      "published": "2026-09-02T16:17:33+00:00",
      "updated": "2026-09-03T18:12:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-85501",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to some of them. TagTrap, where  the triple(Zone, Algo, KeyTag) matching mechanism introduces a significant attack vector when resolvers handle malicious responses containing numerous mismatched DNSKEY, RRSIG, and DS record. DelegationTrap, where constructing the chain-of-trust requires iterative validation of DNSKEY and DS records from the root zone downward. For deeply nested domains, this results in significant computational overhead. NsecTrap, where  responses with excessive invalid NSEC records compel the resolver to validate each one. AdditionalTrap, where Unbound by default would try to DNSSEC validate the ADDITIONAL section as well. This can be exploited to waste validation resources by malicious users.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-85501"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-85501"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85501"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-85501"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-85501.txt"
        }
      ],
      "published": "2026-09-16T09:17:06+00:00",
      "updated": "2026-09-23T19:10:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.14.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.14.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-86138",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.",
      "recommendation": "Upgrade libxml2 to version 2.9.7-21.el8_10.9",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86138"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71585"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86138"
        },
        {
          "url": "https://bugzilla.redhat.com/2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/2529697"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529697"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86140"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86142"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86143"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86144"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71585.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71585"
        },
        {
          "url": "https://github.com/GNOME/libxml2/commit/a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4"
        },
        {
          "url": "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-86138.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86138"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8910-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86138"
        }
      ],
      "published": "2026-09-05T05:17:12+00:00",
      "updated": "2026-09-15T19:40:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-86140",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.",
      "recommendation": "Upgrade libxml2 to version 2.9.7-21.el8_10.9",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86140"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71585"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86140"
        },
        {
          "url": "https://bugzilla.redhat.com/2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/2529697"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529697"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86140"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86142"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86143"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86144"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71585.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71585"
        },
        {
          "url": "https://github.com/GNOME/libxml2/commit/d1686f91dbda141a752200419d35639fd6b38340"
        },
        {
          "url": "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-86140.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86140"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8787-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86140"
        }
      ],
      "published": "2026-09-05T05:17:12+00:00",
      "updated": "2026-09-15T19:39:17+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-86142",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86142"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71585"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86142"
        },
        {
          "url": "https://bugzilla.redhat.com/2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/2529697"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529697"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86140"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86142"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86143"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86144"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71585.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71585"
        },
        {
          "url": "https://github.com/GNOME/libxml2/commit/6b3a736c0edc74ceec3d82f5252499d7911b3a58"
        },
        {
          "url": "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1113"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-86142.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71586.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86142"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8910-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86142"
        }
      ],
      "published": "2026-09-05T05:17:13+00:00",
      "updated": "2026-09-15T19:35:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-86143",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.3,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        192
      ],
      "description": "In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.",
      "recommendation": "Upgrade libxml2 to version 2.9.7-21.el8_10.9",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86143"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71585"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86143"
        },
        {
          "url": "https://bugzilla.redhat.com/2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/2529697"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529697"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86140"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86142"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86143"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86144"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71585.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71585"
        },
        {
          "url": "https://github.com/GNOME/libxml2/commit/90f293ba74d28b1d570920382e707586f68ebf35"
        },
        {
          "url": "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-86143.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86143"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8910-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86143"
        }
      ],
      "published": "2026-09-05T05:17:13+00:00",
      "updated": "2026-09-15T19:31:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-86144",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        669
      ],
      "description": "In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).",
      "recommendation": "Upgrade libxml2 to version 2.9.7-21.el8_10.9",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86144"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71585"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86144"
        },
        {
          "url": "https://bugzilla.redhat.com/2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/2529697"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529697"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86140"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86142"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86143"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86144"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71585.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71585"
        },
        {
          "url": "https://github.com/GNOME/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61"
        },
        {
          "url": "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-86144.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86144"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8910-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86144"
        }
      ],
      "published": "2026-09-05T05:17:13+00:00",
      "updated": "2026-09-15T19:20:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.7?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-86145",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        424
      ],
      "description": "PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86145"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/09/05/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86145"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86145"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86145"
        }
      ],
      "published": "2026-09-05T06:17:10+00:00",
      "updated": "2026-09-09T16:04:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "10.32-3.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-86469",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        59
      ],
      "description": "A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86469"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86469"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2473839"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/blob/main/gio/glocalfileoutputstream.c"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/work_items/4044"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86469"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86469"
        }
      ],
      "published": "2026-09-07T16:17:30+00:00",
      "updated": "2026-09-08T19:08:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-177.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glib2@2.56.4-177.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-8674",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        617
      ],
      "description": "Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8674"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/09/17/4"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8674"
        },
        {
          "url": "https://joshua.hu/fuzzing-glibc-libresolv"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8674"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=31026"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8674"
        }
      ],
      "published": "2026-09-17T17:16:53+00:00",
      "updated": "2026-09-18T18:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-86805",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        367
      ],
      "description": "A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86805"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86805"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86805"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34360"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86805"
        }
      ],
      "published": "2026-09-22T16:18:06+00:00",
      "updated": "2026-09-23T04:17:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-88647",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "description": "A hostname verification bypass in GnuTLS v3.8.13 allows attackers to circumvent the Common Name fallback mechanism and eavesdrop on communications via a crafted certificate.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-88647"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-88647"
        },
        {
          "url": "https://gist.github.com/lkloliver/f98ec3de1a871fdfc02b70b8b9ba7642"
        },
        {
          "url": "https://gitlab.com/gnutls/gnutls/-/issues/1802"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88647"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88647"
        }
      ],
      "published": "2026-10-08T17:17:17+00:00",
      "updated": "2026-10-08T21:33:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.16-8.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ]
    },
    {
      "id": "CVE-2026-88648",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "description": "Incomplete X.509 implementation in GnuTLS v3.8.13 allows attackers controlling a subordinate Certificate Authority to bypass cross-domain PKI restrictions and issue unauthorized certificates.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-88648"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-88648"
        },
        {
          "url": "https://gist.github.com/lkloliver/1f2a97cb8d0b31aa27b6bd0354358d7d"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88648"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88648"
        },
        {
          "url": "https://www.rfc-editor.org/rfc/rfc5280#section-4.2.1.10"
        },
        {
          "url": "https://www.rfc-editor.org/rfc/rfc5280#section-6.1.4"
        }
      ],
      "published": "2026-10-08T19:20:52+00:00",
      "updated": "2026-10-08T21:33:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.16-8.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ]
    },
    {
      "id": "CVE-2026-88806",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-88806"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-88806"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/309"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88806"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88806"
        }
      ],
      "published": "2026-09-21T14:17:22+00:00",
      "updated": "2026-09-22T19:40:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.6.8-9.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.6.8-9.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-88807",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.3,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A heap overflow in libXrender before 0.9.13 in\u00a0RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-88807"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-88807"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxrender/-/merge_requests/19"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88807"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88807"
        }
      ],
      "published": "2026-09-21T14:17:22+00:00",
      "updated": "2026-09-22T19:40:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.10-7.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-89092",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        789
      ],
      "description": "The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.\u00a0 During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.\u00a0 In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89092"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/09/11/2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89092"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89092"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34624"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0016"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89092"
        }
      ],
      "published": "2026-09-11T02:18:35+00:00",
      "updated": "2026-09-11T18:17:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-89157",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89157"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89157"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89157"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89157"
        }
      ],
      "published": "2026-09-11T04:18:03+00:00",
      "updated": "2026-09-16T19:25:08+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "10.32-3.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-89158",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89158"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89158"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89158"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89158"
        }
      ],
      "published": "2026-09-11T04:18:03+00:00",
      "updated": "2026-09-16T19:23:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "10.32-3.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-89161",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        590
      ],
      "description": "In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89161"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89161"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/commit/1dcd0cf42a6a7cb62cc9a7c024196733abcfda95%20%28pcre2-10.48-RC1%29"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/pull/937"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89161"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89161"
        }
      ],
      "published": "2026-09-11T04:18:04+00:00",
      "updated": "2026-09-16T19:10:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "10.32-3.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-8924",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        201
      ],
      "description": "A flaw in curl\u2019s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8924"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69125"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8924"
        },
        {
          "url": "https://bugzilla.redhat.com/2496759"
        },
        {
          "url": "https://bugzilla.redhat.com/2496760"
        },
        {
          "url": "https://bugzilla.redhat.com/2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/2496765"
        },
        {
          "url": "https://bugzilla.redhat.com/2496767"
        },
        {
          "url": "https://bugzilla.redhat.com/2496771"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496759"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496760"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496765"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496767"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496771"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8924.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8924.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8924.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11856"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8458"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8924"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8926"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8932"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9079"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-69125.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69125"
        },
        {
          "url": "https://github.com/advisories/GHSA-hm6c-rc5h-32m9"
        },
        {
          "url": "https://hackerone.com/reports/3733905"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8924.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69125.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8924"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8924"
        }
      ],
      "published": "2026-07-03T07:16:24+00:00",
      "updated": "2026-09-15T07:16:32+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-8927",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        294
      ],
      "description": "When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8927"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69126"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8927"
        },
        {
          "url": "https://bugzilla.redhat.com/2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/2496769"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496769"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8927.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8927.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8927.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8458"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8927"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-69126.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69126"
        },
        {
          "url": "https://github.com/advisories/GHSA-jr4f-4564-w3mr"
        },
        {
          "url": "https://hackerone.com/reports/3744543"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8927.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69126.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8927"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8820-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8927"
        }
      ],
      "published": "2026-07-03T07:16:25+00:00",
      "updated": "2026-09-15T07:16:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-8932",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        305
      ],
      "description": "libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8932"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69125"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8932"
        },
        {
          "url": "https://bugzilla.redhat.com/2496759"
        },
        {
          "url": "https://bugzilla.redhat.com/2496760"
        },
        {
          "url": "https://bugzilla.redhat.com/2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/2496765"
        },
        {
          "url": "https://bugzilla.redhat.com/2496767"
        },
        {
          "url": "https://bugzilla.redhat.com/2496771"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496759"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496760"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496765"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496767"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496771"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8932.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8932.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8932.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11856"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8458"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8924"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8926"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8932"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9079"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-69125.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69125"
        },
        {
          "url": "https://github.com/advisories/GHSA-m7xm-hf59-w6rj"
        },
        {
          "url": "https://hackerone.com/reports/3733910"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8932.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69125.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8932"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8670-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8670-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8670-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8932"
        }
      ],
      "published": "2026-07-03T07:16:25+00:00",
      "updated": "2026-09-15T07:16:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.13",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.13?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. curl/libcurl is base-image tooling; CP application code never drives the vulnerable mTLS connection-reuse pattern."
      }
    },
    {
      "id": "CVE-2026-9076",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)\nprocesses attacker-supplied CMS data, an attacker-chosen stream-mode KEK\ncipher can trigger a heap out-of-bounds read in kek_unwrap_key().\n\nImpact summary: A heap buffer over-read may trigger a crash which leads to\nDenial of Service for an application if the input buffer ends at a memory\npage boundary and the following page is unmapped. There is no information\ndisclosure as the over-read bytes are not revealed to the attacker.\n\nThe key unwrapping function performs a check-byte test as specified in the\nRFC that reads 7 bytes from a heap allocation that is based on the wrapped\nkey length from the message. There is a minimum length check based on the\nblock length of the wrapping cipher. However the cipher is selected from\nan OID carried in the attacker's PWRI keyEncryptionAlgorithm with no\nrequirement that the cipher be a block cipher. When an attacker selects\na stream-mode cipher the guard will be ineffective and the allocated buffer\ncontaining the unwrapped key can be too small to fit the check-bytes\nspecified in the RFC and a buffer over-read can happen.\n\nApplications calling CMS_decrypt() or CMS_decrypt_set1_password()\n(equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS\ndata are vulnerable to this issue. No password knowledge is required: the\nover-read happens during the unwrap attempt before any authentication\nsucceeds.\n\nThe over-read is limited to a few bytes and is not written to output, so\nthere is no information disclosure. Triggering a crash requires the\nallocation to border unmapped memory, which is unlikely with the normal\nallocator.\n\nThe FIPS modules are not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-9076"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-9076"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-q98x-73c3-57gj"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/05b066366842f930fadd9a6e94df98030af431bb"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/715349a1d7c6db970e6815dafb90915f07307f98"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6"
        },
        {
          "url": "https://github.com/openssl/security/commit/05b066366842f930fadd9a6e94df98030af431bb"
        },
        {
          "url": "https://github.com/openssl/security/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0"
        },
        {
          "url": "https://github.com/openssl/security/commit/715349a1d7c6db970e6815dafb90915f07307f98"
        },
        {
          "url": "https://github.com/openssl/security/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26"
        },
        {
          "url": "https://github.com/openssl/security/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-9076.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9076"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9076"
        }
      ],
      "published": "2026-06-09T17:17:50+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-90781",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "cwes": [
        193
      ],
      "description": "alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-90781"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-90781"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/control/ctlparse.c#L216-L241"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/commit/f84cd4ced7b36fddb8e4ee24404cf7c091d27020"
        },
        {
          "url": "https://lore.kernel.org/alsa-devel/CACBQ=P2FhO3M6dkv3cWuKb6Qhs92ouV+FJ3SJZ_PVBSSdJWRAQ@mail.gmail.com/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90781"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-90781"
        },
        {
          "url": "https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-off-by-one-stack-buffer-overflow-in-snd-ctl-ascii-elem-id-parse"
        }
      ],
      "published": "2026-09-13T13:16:29+00:00",
      "updated": "2026-09-24T20:47:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.2.10-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-9149",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-9149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21333"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28236"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-9149"
        },
        {
          "url": "https://bugzilla.redhat.com/2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/2460425"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460425"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48864"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9149"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9150"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-28236.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28236"
        },
        {
          "url": "https://github.com/openSUSE/libsolv/pull/617"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-9149.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-28236.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9149"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9149"
        }
      ],
      "published": "2026-05-21T00:16:35+00:00",
      "updated": "2026-09-01T12:17:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.7.20-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-93541",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-93541"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-93541"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=7b6fffd13fd3914e0b39f3a4f131913da7f066e7"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93541"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93541"
        }
      ],
      "published": "2026-09-24T16:17:26+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.7.10-1.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-93542",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-93542"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-93542"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=f499944ad595b9bd7e7571c810842244caf150aa"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93542"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93542"
        }
      ],
      "published": "2026-09-24T17:17:10+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.7.10-1.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-93543",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-93543"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-93543"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=e2089ab748828273f916bbffd4e65b506aa50fdc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93543"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93543"
        }
      ],
      "published": "2026-09-24T17:17:10+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.7.10-1.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-93544",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-93544"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-93544"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=a88a341135b79f6ed450f481e4a5d6ba502382af"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93544"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93544"
        }
      ],
      "published": "2026-09-24T17:17:10+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.7.10-1.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-93545",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-93545"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-93545"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=234ce17d95c42d75f7f7fdb2bf7a24875451bc0a"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93545"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93545"
        }
      ],
      "published": "2026-09-24T17:17:10+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.7.10-1.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-93990",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        176
      ],
      "description": "Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds.",
      "recommendation": "Upgrade expat to version 2.5.0-4.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-93990"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72663"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-93990"
        },
        {
          "url": "https://blog.hartwork.org/posts/expat-2-8-5-released/"
        },
        {
          "url": "https://bugzilla.redhat.com/2538967"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517901"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2538967"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-66046"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-93990"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-72663.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:72663"
        },
        {
          "url": "https://github.com/libexpat/libexpat"
        },
        {
          "url": "https://github.com/libexpat/libexpat/commit/ff6e1d7e750bbe245178f51a47a965dc8342861a"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1282"
        },
        {
          "url": "https://github.com/libexpat/libexpat/releases/tag/R_2_8_5"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-93990.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-74001.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93990"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93990"
        },
        {
          "url": "https://www.vulncheck.com/advisories/expat-through-2.8.4-malformed-utf-16-acceptance-via-unchecked-surrogate"
        }
      ],
      "published": "2026-09-19T23:17:10+00:00",
      "updated": "2026-09-28T17:17:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-94281",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94281"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-94281"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=605f419d013153bf9e026cd100752ffbe930f3c1"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94281"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94281"
        }
      ],
      "published": "2026-09-24T17:17:16+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.7.10-1.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libXi@1.7.10-1.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-94283",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94283"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-94283"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=42d0303f243002a9856c76060569a61893c670dd"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94283"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94283"
        }
      ],
      "published": "2026-09-28T09:17:08+00:00",
      "updated": "2026-09-30T13:17:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.6.8-9.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.6.8-9.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-94284",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94284"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-94284"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=1b7904002d212eed40949ccf4e8e7156f9fec0e2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94284"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94284"
        }
      ],
      "published": "2026-09-28T09:17:08+00:00",
      "updated": "2026-09-30T13:17:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.6.8-9.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.6.8-9.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-94285",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94285"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-94285"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=980868483446f24f9658d26aa5bfa42f3da6dd3a"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94285"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94285"
        }
      ],
      "published": "2026-09-28T09:17:08+00:00",
      "updated": "2026-09-30T13:17:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.6.8-9.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.6.8-9.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libX11-common@1.6.8-9.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libX11@1.6.8-9.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-94286",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "cwes": [
        126
      ],
      "description": "An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94286"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-94286"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxtst/-/merge_requests/10/diffs?commit_id=16023c86070e6af9407330deea3938fcef75815b"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94286"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94286"
        }
      ],
      "published": "2026-09-28T09:17:08+00:00",
      "updated": "2026-09-30T13:17:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.2.3-7.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libXtst@1.2.3-7.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-95512",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-95512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74952"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-95512"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2462295"
        },
        {
          "url": "https://gitlab.freedesktop.org/freetype/freetype/-/commit/f3ca71c9900fe860849b3163a6e2c1e765b291d9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95512"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8881-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-95512"
        }
      ],
      "published": "2026-10-02T09:16:45+00:00",
      "updated": "2026-10-06T03:17:09+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.1-10.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/freetype@2.9.1-10.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-95519",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        78
      ],
      "description": "A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries are unexpectedly macro-expanded before being opened, allowing embedded shell commands to run with the privileges of the `rpm` process. Successful exploitation can lead to a full compromise of confidentiality, integrity, and availability for the affected account.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-95519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-95519"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2470977"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95519"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-95519"
        }
      ],
      "published": "2026-09-24T14:18:20+00:00",
      "updated": "2026-09-25T13:17:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-95520",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in iterReadArchiveNext() that shrinks a buffer allocation to one byte, after which the payload's independently-controlled cpio filesize field is used to write attacker-controlled data past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an  untrusted package.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-95520"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-95520"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2537809"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95520"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-95520"
        }
      ],
      "published": "2026-09-29T12:17:12+00:00",
      "updated": "2026-09-29T21:29:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-95521",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        78
      ],
      "description": "A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an untrusted .src.rpm.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-95521"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-95521"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2537812"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95521"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-95521"
        }
      ],
      "published": "2026-09-24T14:18:20+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-95619",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-95619"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58503"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67275"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-95619"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2537811"
        },
        {
          "url": "https://gcc.gnu.org/pipermail/gcc-patches/2026-September/732381.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95619"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-95619"
        }
      ],
      "published": "2026-09-22T13:17:13+00:00",
      "updated": "2026-09-22T19:37:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-95818",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        121
      ],
      "description": "A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-95818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-95818"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95818"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34360"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-95818"
        }
      ],
      "published": "2026-09-22T17:17:32+00:00",
      "updated": "2026-09-22T19:56:19+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-96674",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology files that wrap size calculations, causing the decoder to read beyond the topology buffer and potentially leak sensitive data or crash the application.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-96674"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-96674"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1316-L1326"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1420-L1430"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1511-L1521"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/pull/527"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-96674"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-96674"
        },
        {
          "url": "https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-integer-overflow-via-topology-file"
        }
      ],
      "published": "2026-09-23T16:16:50+00:00",
      "updated": "2026-09-24T21:08:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.2.10-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-96675",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        129
      ],
      "description": "alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers can supply a malicious ALSA configuration file with sparse bindings to trigger an out-of-bounds array read and assertion failure, causing the application to abort.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-96675"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-96675"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/pcm/pcm_multi.c#L1122-L1131"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/pull/527"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-96675"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-96675"
        },
        {
          "url": "https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-denial-of-service-via-pcm-multi"
        }
      ],
      "published": "2026-09-23T16:16:50+00:00",
      "updated": "2026-09-24T21:08:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.2.10-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-97399",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        126
      ],
      "description": "The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-97399"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/09/28/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-97399"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97399"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34683"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-97399"
        }
      ],
      "published": "2026-09-28T16:17:18+00:00",
      "updated": "2026-09-29T21:36:39+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f8ba1175-ab7b-4483-88a3-24b41bd368a9/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-97687",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        295,
        440
      ],
      "description": "urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail to remain separated because target-server TLS settings are incorrectly applied to the HTTPS proxy connection. The trigger is that an application uses an HTTPS proxy and configures target-server TLS settings that must remain separate from the proxy TLS handshake, including HTTPS forwarding with target-specific identity or credentials. Applying cert_reqs=CERT_NONE can overwrite proxy_ssl_context.verify_mode in place, and the mutation persists so later connections reusing the same context may connect to the HTTPS proxy without certificate verification. The attack mechanism is that an attacker intercepts and impersonates the HTTPS proxy after the effective proxy policy accepts the attacker's certificate. The impact is that the attacker can observe or modify forwarded traffic or receive a target TLS client certificate, while CONNECT tunneling still preserves the separate end-to-end target TLS connection. This issue is fixed in version 2.8.0.",
      "recommendation": "Upgrade urllib3 to version 2.8.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-97687"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-97687"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-97687"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/07408cec79d1856d81bb42c74a904a24fdb9e465"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/b6447295fff7b38fdffc67e0df9712d60cef3cc3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/pull/5093"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.8.0"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97687"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-97687"
        }
      ],
      "published": "2026-09-29T16:17:18+00:00",
      "updated": "2026-09-30T21:17:19+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.7.0",
          "versions": [
            {
              "version": "2.7.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:pypi/urllib3@2.7.0",
          "versions": [
            {
              "version": "2.7.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:pypi/urllib3@2.7.0"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-97688",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        835
      ],
      "description": "urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Transfer-Encoding: chunked and Content-Encoding: deflate, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0.",
      "recommendation": "Upgrade urllib3 to version 2.8.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-97688"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-97688"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-97688"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.8.0"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97688"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-97688"
        }
      ],
      "published": "2026-09-29T16:17:18+00:00",
      "updated": "2026-09-30T19:38:27+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.7.0",
          "versions": [
            {
              "version": "2.7.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:pypi/urllib3@2.7.0",
          "versions": [
            {
              "version": "2.7.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:pypi/urllib3@2.7.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-97689",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0.",
      "recommendation": "Upgrade urllib3 to version 2.8.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-97689"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-97689"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-97689"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.8.0"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97689"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-97689"
        }
      ],
      "published": "2026-09-29T16:17:18+00:00",
      "updated": "2026-09-30T19:38:27+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.7.0",
          "versions": [
            {
              "version": "2.7.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:pypi/urllib3@2.7.0",
          "versions": [
            {
              "version": "2.7.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:pypi/urllib3@2.7.0"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:pypi/urllib3@2.7.0"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "GHSA-6v7p-g79w-8964",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "description": "### Impact\n\nIf the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV.\n\nIf the Unpacker is used repeatedly to unpack untrusted input from external sources, it may be vulnerable to a DoS attack.\n\n### Patches\n\nv1.2.1\n\n### Workarounds\n\nUsers should create a new Unpacker instead of reusing the same Unpacker after an error occurs.\n\nApplying the above patch can prevent SEGV, but reusing the Streaming Unpacker after it has encountered an error will not yield correct data. If an error occurs during Streaming Unpacking, the Stream and Streaming Unpacker should be discarded.\n\nTherefore, this is not just a workaround but the correct solution. The above patch only prevents crashes from incorrect usage.",
      "recommendation": "Upgrade msgpack to version 1.2.1",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-6v7p-g79w-8964"
        },
        {
          "url": "https://advisory.echohq.com/cve/GHSA-6v7p-g79w-8964"
        },
        {
          "url": "https://github.com/msgpack/msgpack-python"
        },
        {
          "url": "https://github.com/msgpack/msgpack-python/commit/2c56ddb5d0025ed481d962c0f5d62d19dec7476d"
        },
        {
          "url": "https://github.com/msgpack/msgpack-python/releases/tag/v1.2.1"
        },
        {
          "url": "https://github.com/msgpack/msgpack-python/security/advisories/GHSA-6v7p-g79w-8964"
        }
      ],
      "published": "2026-06-19T21:42:55+00:00",
      "updated": "2026-06-19T21:42:55+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/msgpack@1.1.2",
          "versions": [
            {
              "version": "1.1.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a7cb7348-67c3-41b7-80e9-5dfe12f6841f/1#pkg:pypi/msgpack@1.1.2"
        },
        {
          "ref": "urn:cdx:e268dda4-1311-48ba-b7d7-119ae0620e69/1#pkg:pypi/msgpack@1.1.2"
        },
        {
          "ref": "urn:cdx:84f868a5-270d-4e74-883f-aa7e2bdd4bf1/1#pkg:pypi/msgpack@1.1.2"
        },
        {
          "ref": "urn:cdx:7958d468-6c09-4135-a20b-cc7256e64c68/1#pkg:pypi/msgpack@1.1.2"
        },
        {
          "ref": "urn:cdx:003d5ed4-7fa8-4eaa-9ef1-cfecaa78acfb/1#pkg:pypi/msgpack@1.1.2"
        },
        {
          "ref": "urn:cdx:681bc2d7-c90a-4fea-bf43-e857cf42583c/1#pkg:pypi/msgpack@1.1.2"
        },
        {
          "ref": "urn:cdx:00180cd0-80f7-46a9-be87-bbebfa4f0d16/1#pkg:pypi/msgpack@1.1.2"
        },
        {
          "ref": "urn:cdx:7bb50b37-c19a-40fc-ac02-c84b0ed5ef3c/1#pkg:pypi/msgpack@1.1.2"
        },
        {
          "ref": "urn:cdx:f488f36b-0eb8-4db9-841d-c681122863b8/1#pkg:pypi/msgpack@1.1.2"
        },
        {
          "ref": "urn:cdx:0b1db290-81c3-4e45-8430-a405d46df8df/1#pkg:pypi/msgpack@1.1.2"
        },
        {
          "ref": "urn:cdx:7b6dd280-4429-4a19-b8cc-b7648573228c/1#pkg:pypi/msgpack@1.1.2"
        },
        {
          "ref": "urn:cdx:5fb1c76b-c085-479a-987e-795b6c0b19b1/1#pkg:pypi/msgpack@1.1.2"
        },
        {
          "ref": "urn:cdx:61588213-29b4-4798-b6be-f97a1ab14b7e/1#pkg:pypi/msgpack@1.1.2"
        },
        {
          "ref": "urn:cdx:431dafb0-3763-4649-857b-9e08b69e96aa/1#pkg:pypi/msgpack@1.1.2"
        },
        {
          "ref": "urn:cdx:0681d191-d1a5-4b80-9856-d2845d2a2fc7/1#pkg:pypi/msgpack@1.1.2"
        },
        {
          "ref": "urn:cdx:386cc85e-0834-4d85-b507-56b4002287f3/1#pkg:pypi/msgpack@1.1.2"
        },
        {
          "ref": "urn:cdx:d193778a-9395-4cdb-9220-b74293c20186/1#pkg:pypi/msgpack@1.1.2"
        },
        {
          "ref": "urn:cdx:b61f5c4a-5f81-49ec-836d-f37539b92904/1#pkg:pypi/msgpack@1.1.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. No CP source repo declares msgpack directly; the most plausible bundling path (pip's vendored copy) is exercised only at image-build time, not at product runtime."
      }
    },
    {
      "id": "CVE-2026-39824",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "cwes": [
        190
      ],
      "description": "NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.",
      "recommendation": "Upgrade golang.org/x/sys to version 0.44.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39824"
        },
        {
          "url": "https://go.dev/cl/770080"
        },
        {
          "url": "https://go.dev/issue/78916"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5024"
        }
      ],
      "published": "2026-05-22T20:16:33+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/sys@v0.7.0",
          "versions": [
            {
              "version": "v0.7.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/sys@v0.22.0",
          "versions": [
            {
              "version": "v0.22.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:golang/golang.org/x/sys@v0.7.0"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:golang/golang.org/x/sys@v0.7.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/sys@v0.22.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56857",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56857"
        },
        {
          "url": "https://go.dev/cl/847305"
        },
        {
          "url": "https://go.dev/issue/81739"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6604"
        }
      ],
      "published": "2026-10-08T23:17:01+00:00",
      "updated": "2026-10-08T23:17:01+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56866",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56866"
        },
        {
          "url": "https://go.dev/cl/847306"
        },
        {
          "url": "https://go.dev/issue/81740"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6605"
        }
      ],
      "published": "2026-10-08T23:17:01+00:00",
      "updated": "2026-10-08T23:17:01+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-78659",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78659"
        },
        {
          "url": "https://go.dev/cl/847185"
        },
        {
          "url": "https://go.dev/cl/847314"
        },
        {
          "url": "https://go.dev/issue/81857"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6603"
        }
      ],
      "published": "2026-10-08T23:17:03+00:00",
      "updated": "2026-10-08T23:17:03+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/net@v0.25.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-78660",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78660"
        },
        {
          "url": "https://go.dev/cl/835145"
        },
        {
          "url": "https://go.dev/cl/836385"
        },
        {
          "url": "https://go.dev/issue/81115"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6610"
        }
      ],
      "published": "2026-10-08T23:17:03+00:00",
      "updated": "2026-10-08T23:17:03+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/net@v0.25.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-78663",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78663"
        },
        {
          "url": "https://go.dev/cl/847187"
        },
        {
          "url": "https://go.dev/cl/847310"
        },
        {
          "url": "https://go.dev/issue/81743"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6612"
        }
      ],
      "published": "2026-10-08T23:17:03+00:00",
      "updated": "2026-10-08T23:17:03+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/net@v0.25.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-78667",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "description": "When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78667"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-78667"
        },
        {
          "url": "https://go.dev/cl/847309"
        },
        {
          "url": "https://go.dev/issue/81858"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78667"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6609"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78667"
        }
      ],
      "published": "2026-10-08T23:17:03+00:00",
      "updated": "2026-10-08T23:17:03+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-78669",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78669"
        },
        {
          "url": "https://go.dev/cl/847186"
        },
        {
          "url": "https://go.dev/cl/847308"
        },
        {
          "url": "https://go.dev/issue/81742"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6611"
        }
      ],
      "published": "2026-10-08T23:17:04+00:00",
      "updated": "2026-10-08T23:17:04+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/net@v0.25.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-94439",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "description": "When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-94439"
        },
        {
          "url": "https://go.dev/cl/847311"
        },
        {
          "url": "https://go.dev/issue/81744"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94439"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6613"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94439"
        }
      ],
      "published": "2026-10-08T23:17:04+00:00",
      "updated": "2026-10-08T23:17:04+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-94440",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94440"
        },
        {
          "url": "https://go.dev/cl/847307"
        },
        {
          "url": "https://go.dev/issue/81741"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6608"
        }
      ],
      "published": "2026-10-08T23:17:04+00:00",
      "updated": "2026-10-08T23:17:04+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-94448",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94448"
        },
        {
          "url": "https://go.dev/cl/839866"
        },
        {
          "url": "https://go.dev/issue/81821"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6599"
        }
      ],
      "published": "2026-10-08T23:17:05+00:00",
      "updated": "2026-10-08T23:17:05+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-97030",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-97030"
        },
        {
          "url": "https://go.dev/cl/840925"
        },
        {
          "url": "https://go.dev/issue/81823"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6600"
        }
      ],
      "published": "2026-10-08T23:17:05+00:00",
      "updated": "2026-10-08T23:17:05+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-97031",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "description": "Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-97031"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-97031"
        },
        {
          "url": "https://go.dev/cl/847312"
        },
        {
          "url": "https://go.dev/issue/81855"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97031"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6607"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-97031"
        }
      ],
      "published": "2026-10-08T23:17:06+00:00",
      "updated": "2026-10-08T23:17:06+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-97032",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "description": "HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-97032"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-97032"
        },
        {
          "url": "https://go.dev/cl/847188"
        },
        {
          "url": "https://go.dev/cl/847313"
        },
        {
          "url": "https://go.dev/issue/81867"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97032"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6617"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-97032"
        }
      ],
      "published": "2026-10-08T23:17:06+00:00",
      "updated": "2026-10-08T23:17:06+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:30f1dabd-dfe9-4622-8a3b-d8803491113d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:a66df83a-1e27-4e0b-912e-d50fa8f11067/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/net@v0.25.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2024-45336",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.",
      "recommendation": "Upgrade stdlib to version 1.22.11, 1.23.5, 1.24.0-rc.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-45336"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:3773"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66016"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-45336"
        },
        {
          "url": "https://bugzilla.redhat.com/2315719"
        },
        {
          "url": "https://bugzilla.redhat.com/2341751"
        },
        {
          "url": "https://bugzilla.redhat.com/2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2310528"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2341750"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2341751"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2344219"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34156"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45336"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45341"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22866"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-66016.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:3773"
        },
        {
          "url": "https://github.com/golang/go/issues/70530"
        },
        {
          "url": "https://go.dev/cl/643100"
        },
        {
          "url": "https://go.dev/issue/70530"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/sSaUhLA-2SI"
        },
        {
          "url": "https://groups.google.com/g/golang-dev/c/CAWXhan3Jww/m/bk9LAa-lCgAJ"
        },
        {
          "url": "https://groups.google.com/g/golang-dev/c/bG8cv1muIBM/m/G461hA6lCgAJ"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-45336.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-7592.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45336"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-3420"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250221-0003/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7574-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-45336"
        }
      ],
      "published": "2025-01-28T02:15:28+00:00",
      "updated": "2026-06-17T07:54:03+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2024-45337",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that \"A call to this function does not guarantee that the key offered is in fact used to authenticate.\" Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used to infer which key the client successfully authenticated with, if any. Some applications, which store the key(s) passed to PublicKeyCallback (or derived information) and make security relevant determinations based on it once the connection is established, may make incorrect assumptions. For example, an attacker may send public keys A and B, and then authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B for which the attacker does not actually control the private key. Since this API is widely misused, as a partial mitigation golang.org/x/cry...@v0.31.0 enforces the property that, when successfully authenticating via public key, the last key passed to ServerConfig.PublicKeyCallback will be the key used to authenticate the connection. PublicKeyCallback will now be called multiple times with the same key, if necessary. Note that the client may still not control the last key passed to PublicKeyCallback if the connection is then authenticated with a different method, such as PasswordCallback, KeyboardInteractiveCallback, or NoClientAuth. Users should be using the Extensions field of the Permissions return value from the various authentication callbacks to record data associated with the authentication attempt instead of referencing external state. Once the connection is established the state corresponding to the successful authentication attempt can be retrieved via the ServerConn.Permissions field. Note that some third-party libraries misuse the Permissions type by sharing it across authentication attempts; users of third-party libraries should refer to the relevant projects for guidance.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.31.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-45337"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/12/11/2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-45337"
        },
        {
          "url": "https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909"
        },
        {
          "url": "https://go-review.googlesource.com/c/crypto/+/635315/"
        },
        {
          "url": "https://go.dev/cl/635315"
        },
        {
          "url": "https://go.dev/issue/70779"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/-nPEi39gI4Q/m/cGVPJCqdAQAJ"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45337"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2024-3321"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0007/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7839-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7839-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-45337"
        }
      ],
      "published": "2024-12-12T02:02:07+00:00",
      "updated": "2026-06-17T07:54:03+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2024-45338",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1333
      ],
      "description": "An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.",
      "recommendation": "Upgrade golang.org/x/net to version 0.33.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-45338"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45338"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-45338"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/8.2.0/BRSA-newyz3jucdu5.toml"
        },
        {
          "url": "https://go-review.googlesource.com/c/net/+/637536"
        },
        {
          "url": "https://go.dev/cl/637536"
        },
        {
          "url": "https://go.dev/issue/70906"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/wSCRmFnNmPA/m/Lvcd0mRMAwAJ"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45338"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2024-3333"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250221-0001/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7197-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8900-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-45338"
        }
      ],
      "published": "2024-12-18T21:15:08+00:00",
      "updated": "2026-06-17T07:54:03+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/net@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2024-45341",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.",
      "recommendation": "Upgrade stdlib to version 1.22.11, 1.23.5, 1.24.0-rc.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-45341"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:3772"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:3773"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-45341"
        },
        {
          "url": "https://bugzilla.redhat.com/2341750"
        },
        {
          "url": "https://bugzilla.redhat.com/2341751"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2310528"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2341750"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2341751"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2344219"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34156"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45336"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45341"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22866"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2025-3772.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:3773"
        },
        {
          "url": "https://github.com/golang/go/commit/2b2314e9f6103de322b2e247387c8b01fd0cd5a4"
        },
        {
          "url": "https://github.com/golang/go/issues/71156"
        },
        {
          "url": "https://go.dev/cl/643099"
        },
        {
          "url": "https://go.dev/issue/71156"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/sSaUhLA-2SI"
        },
        {
          "url": "https://groups.google.com/g/golang-dev/c/CAWXhan3Jww/m/bk9LAa-lCgAJ"
        },
        {
          "url": "https://groups.google.com/g/golang-dev/c/bG8cv1muIBM/m/G461hA6lCgAJ"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-45341.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-7466.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45341"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-3373"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250221-0004/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7574-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-45341"
        }
      ],
      "published": "2025-01-28T02:15:29+00:00",
      "updated": "2026-06-17T07:54:03+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-0913",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        59
      ],
      "description": "os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink to a nonexistent location, OpenFile would create a file in that location. OpenFile now always returns an error when the O_CREATE and O_EXCL flags are both set and the target path is a symlink.",
      "recommendation": "Upgrade stdlib to version 1.23.10, 1.24.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-0913"
        },
        {
          "url": "https://go.dev/cl/672396"
        },
        {
          "url": "https://go.dev/issue/73702"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0913"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-3750"
        }
      ],
      "published": "2025-06-11T18:15:24+00:00",
      "updated": "2026-06-17T08:27:21+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-21613",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        88
      ],
      "description": "go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.",
      "recommendation": "Upgrade github.com/go-git/go-git/v5 to version 5.13.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-21613"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:0401"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-21613"
        },
        {
          "url": "https://bugzilla.redhat.com/2335888"
        },
        {
          "url": "https://bugzilla.redhat.com/2335901"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2335888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2335901"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21613"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21614"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2025-0401.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:0401"
        },
        {
          "url": "https://github.com/go-git/go-git"
        },
        {
          "url": "https://github.com/go-git/go-git/security/advisories/GHSA-v725-9546-7q7m"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-21613.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-0401.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21613"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-3368"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8088-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-21613"
        }
      ],
      "published": "2025-01-06T17:15:47+00:00",
      "updated": "2026-06-17T08:43:51+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/go-git/go-git/v5@v5.12.0"
        }
      ]
    },
    {
      "id": "CVE-2025-21614",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.",
      "recommendation": "Upgrade github.com/go-git/go-git/v5 to version 5.13.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-21614"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:0401"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-21614"
        },
        {
          "url": "https://bugzilla.redhat.com/2335888"
        },
        {
          "url": "https://bugzilla.redhat.com/2335901"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2335888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2335901"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21613"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21614"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2025-0401.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:0401"
        },
        {
          "url": "https://github.com/go-git/go-git"
        },
        {
          "url": "https://github.com/go-git/go-git/security/advisories/GHSA-r9px-m959-cxf4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-21614.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-0401.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21614"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-3367"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8088-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-21614"
        }
      ],
      "published": "2025-01-06T17:15:47+00:00",
      "updated": "2026-06-17T08:43:51+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/go-git/go-git/v5@v5.12.0"
        }
      ]
    },
    {
      "id": "CVE-2025-22866",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.",
      "recommendation": "Upgrade stdlib to version 1.22.12, 1.23.6, 1.24.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-22866"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:3773"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67148"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-22866"
        },
        {
          "url": "https://bugzilla.redhat.com/2344219"
        },
        {
          "url": "https://bugzilla.redhat.com/2456333"
        },
        {
          "url": "https://bugzilla.redhat.com/2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/2484204"
        },
        {
          "url": "https://bugzilla.redhat.com/2484830"
        },
        {
          "url": "https://bugzilla.redhat.com/2493622"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2310528"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2341750"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2341751"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2344219"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34156"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45336"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45341"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22866"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-67148.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:3773"
        },
        {
          "url": "https://github.com/golang/go/commit/0cc45e7ca668b103c1055ae84402ad3f3425dd56%20%28go1.22.12%29"
        },
        {
          "url": "https://github.com/golang/go/commit/6644ed63b1e6ccc129647ef6b0d4647fdbe14056%20%28go1.23.6%29"
        },
        {
          "url": "https://github.com/golang/go/commit/6fc23a3cff5e38ff72923fee50f51254dcdc6e93%20%28go1.24rc3%29"
        },
        {
          "url": "https://github.com/golang/go/issues/71383"
        },
        {
          "url": "https://go.dev/cl/643735"
        },
        {
          "url": "https://go.dev/issue/71383"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/xU1ZCHUZw3k"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-22866.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67148-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22866"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-3447"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250221-0002/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7574-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-22866"
        }
      ],
      "published": "2025-02-06T17:15:21+00:00",
      "updated": "2026-06-17T08:50:38+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-22868",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        1286
      ],
      "description": "An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.",
      "recommendation": "Upgrade golang.org/x/oauth2 to version 0.27.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-22868"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:7479"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-22868"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2347423"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2348366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2352914"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2354195"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22868"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-27144"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-29786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30204"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:7479"
        },
        {
          "url": "https://go.dev/cl/652155"
        },
        {
          "url": "https://go.dev/issue/71490"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22868"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-3488"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-22868"
        }
      ],
      "published": "2025-02-26T08:14:24+00:00",
      "updated": "2026-06-17T08:50:39+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/oauth2@v0.21.0",
          "versions": [
            {
              "version": "v0.21.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/oauth2@v0.21.0",
          "versions": [
            {
              "version": "v0.21.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/oauth2@v0.21.0",
          "versions": [
            {
              "version": "v0.21.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/oauth2@v0.21.0",
          "versions": [
            {
              "version": "v0.21.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/oauth2@v0.21.0",
          "versions": [
            {
              "version": "v0.21.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/oauth2@v0.21.0"
        }
      ]
    },
    {
      "id": "CVE-2025-22869",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        770
      ],
      "description": "SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.35.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-22869"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:3833"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:7416"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-22869"
        },
        {
          "url": "https://bugzilla.redhat.com/2348367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2348367"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22869"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-3833.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:7416"
        },
        {
          "url": "https://github.com/golang/go/issues/71931"
        },
        {
          "url": "https://go-review.googlesource.com/c/crypto/+/652135"
        },
        {
          "url": "https://go.dev/cl/652135"
        },
        {
          "url": "https://go.dev/issue/71931"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-22869.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-7484.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22869"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-3487"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250411-0010/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8519-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-22869"
        }
      ],
      "published": "2025-02-26T08:14:24+00:00",
      "updated": "2026-06-17T08:50:40+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2025-22870",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        115
      ],
      "description": "Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to \"*.example.com\", a request to \"[::1%25.example.com]:80` will incorrectly match and not be proxied.",
      "recommendation": "Upgrade golang.org/x/net to version 0.36.0; Upgrade stdlib to version 1.23.7, 1.24.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-22870"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22870"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/03/07/2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-22870"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/8.2.0/BRSA-leg349bma1kc.toml"
        },
        {
          "url": "https://github.com/golang/go/issues/71984"
        },
        {
          "url": "https://go.dev/cl/654697"
        },
        {
          "url": "https://go.dev/issue/71984"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/4t3lzH3I0eI/m/b42ImqrBAQAJ"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22870"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-3503"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250509-0007/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7574-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-22870"
        }
      ],
      "published": "2025-03-12T19:15:38+00:00",
      "updated": "2026-06-17T08:50:40+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/net@v0.25.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ]
    },
    {
      "id": "CVE-2025-22871",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.",
      "recommendation": "Upgrade stdlib to version 1.23.8, 1.24.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-22871"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/04/04/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:9635"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-22871"
        },
        {
          "url": "https://bugzilla.redhat.com/2358493"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2358493"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-783943.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22871"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-9635.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:9635"
        },
        {
          "url": "https://github.com/golang/go/issues/71988"
        },
        {
          "url": "https://github.com/roadrunner-server/roadrunner"
        },
        {
          "url": "https://github.com/roadrunner-server/roadrunner/commit/f269279ee87d0b88127741cad1042389af7605fa"
        },
        {
          "url": "https://github.com/roadrunner-server/roadrunner/issues/2166"
        },
        {
          "url": "https://github.com/roadrunner-server/roadrunner/releases/tag/v2025.1.0"
        },
        {
          "url": "https://go.dev/cl/652998"
        },
        {
          "url": "https://go.dev/issue/71988"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/Y2uBTVKjBQk"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/Y2uBTVKjBQk/m/cs_6qIK5BAAJ"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-22871.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-9845.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22871"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-3563"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-22871"
        }
      ],
      "published": "2025-04-08T20:15:20+00:00",
      "updated": "2026-06-17T08:50:41+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "This issue exists in the utilities not directly invoked by Confluent Platform."
      }
    },
    {
      "id": "CVE-2025-22872",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can result in content following such tags as being placed in the wrong scope during DOM construction, but only when tags are in foreign content (e.g. <math>, <svg>, etc contexts).",
      "recommendation": "Upgrade golang.org/x/net to version 0.38.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-22872"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-22872"
        },
        {
          "url": "https://github.com/TheDegenerateDev5150/net/commit/e1fcd82abba34df74614020343be8eb1fe85f0d9"
        },
        {
          "url": "https://github.com/advisories/GHSA-vvgc-356p-c3xw"
        },
        {
          "url": "https://go.dev/cl/662715"
        },
        {
          "url": "https://go.dev/issue/73070"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/ezSKR9vqbqA"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22872"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-3595"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250516-0007/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8089-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8089-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8089-3"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8900-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-22872"
        }
      ],
      "published": "2025-04-16T18:16:04+00:00",
      "updated": "2026-06-17T08:50:41+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/net@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2025-22873",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 3.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        23
      ],
      "description": "It was possible to improperly access the parent directory of an os.Root by opening a filename ending in \"../\". For example, Root.Open(\"../\") would open the parent directory of the Root. This escape only permits opening the parent directory itself, not ancestors of the parent or files contained within the parent.",
      "recommendation": "Upgrade stdlib to version 1.23.9, 1.24.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-22873"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/06/2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-22873"
        },
        {
          "url": "https://go.dev/cl/670036"
        },
        {
          "url": "https://go.dev/issue/73555"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/UZoIkUT367A/m/5WDxKizJAQAJ"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22873"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4403"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-22873"
        }
      ],
      "published": "2026-02-04T23:15:54+00:00",
      "updated": "2026-06-17T08:50:42+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ]
    },
    {
      "id": "CVE-2025-27144",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. In versions on the 4.x branch prior to version 4.0.5, when parsing compact JWS or JWE input, Go JOSE could use excessive memory. The code used strings.Split(token, \".\") to split JWT tokens, which is vulnerable to excessive memory consumption when processing maliciously crafted tokens with a large number of `.` characters.  An attacker could exploit this by sending numerous malformed tokens, leading to memory exhaustion and a Denial of Service. Version 4.0.5 fixes this issue. As a workaround, applications could pre-validate that payloads passed to Go JOSE do not contain an excessive number of `.` characters.",
      "recommendation": "Upgrade github.com/go-jose/go-jose/v3 to version 3.0.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-27144"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:7397"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-27144"
        },
        {
          "url": "https://bugzilla.redhat.com/2347423"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2347423"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-27144"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-7397.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:7397"
        },
        {
          "url": "https://github.com/go-jose/go-jose"
        },
        {
          "url": "https://github.com/go-jose/go-jose/commit/99b346cec4e86d102284642c5dcbe9bb0cacfc22"
        },
        {
          "url": "https://github.com/go-jose/go-jose/releases/tag/v4.0.5"
        },
        {
          "url": "https://github.com/go-jose/go-jose/security/advisories/GHSA-c6gw-w398-hv78"
        },
        {
          "url": "https://github.com/golang/go/issues/71490"
        },
        {
          "url": "https://go.dev/issue/71490"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-27144.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-7467.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27144"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-27144"
        }
      ],
      "published": "2025-02-24T23:15:11+00:00",
      "updated": "2026-06-17T09:03:05+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/go-jose/go-jose/v3@v3.0.3",
          "versions": [
            {
              "version": "v3.0.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-jose/go-jose/v3@v3.0.3",
          "versions": [
            {
              "version": "v3.0.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-jose/go-jose/v3@v3.0.3",
          "versions": [
            {
              "version": "v3.0.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-jose/go-jose/v3@v3.0.3",
          "versions": [
            {
              "version": "v3.0.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-jose/go-jose/v3@v3.0.3",
          "versions": [
            {
              "version": "v3.0.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/go-jose/go-jose/v3@v3.0.3"
        }
      ]
    },
    {
      "id": "CVE-2025-4673",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.",
      "recommendation": "Upgrade stdlib to version 1.23.10, 1.24.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-4673"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:15887"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-4673"
        },
        {
          "url": "https://bugzilla.redhat.com/2373305"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2373305"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4673"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-15887.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:15887"
        },
        {
          "url": "https://go.dev/cl/679257"
        },
        {
          "url": "https://go.dev/issue/73816"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-4673.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-10677.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4673"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-3751"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7574-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-4673"
        }
      ],
      "published": "2025-06-11T17:15:42+00:00",
      "updated": "2026-06-17T09:33:45+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-47906",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "description": "If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath (\"\", \".\", and \"..\"), can result in the binaries listed in the PATH being unexpectedly returned.",
      "recommendation": "Upgrade stdlib to version 1.23.12, 1.24.6",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-47906"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/08/06/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:22005"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-47906"
        },
        {
          "url": "https://bugzilla.redhat.com/2396546"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2396546"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47906"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-22005.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:22005"
        },
        {
          "url": "https://go.dev/cl/691775"
        },
        {
          "url": "https://go.dev/issue/74466"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/x5MKroML2yM"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-47906.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-22668.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47906"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-3956"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-47906"
        }
      ],
      "published": "2025-09-18T19:15:37+00:00",
      "updated": "2026-06-17T09:28:49+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2025-47907",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        362
      ],
      "description": "Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the expected results with those of another query, causing the call to Scan to return either unexpected results from the other query or an error.",
      "recommendation": "Upgrade stdlib to version 1.23.12, 1.24.6",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-47907"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/08/06/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:20909"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-47907"
        },
        {
          "url": "https://bugzilla.redhat.com/2387083"
        },
        {
          "url": "https://bugzilla.redhat.com/2393152"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-20909.html"
        },
        {
          "url": "https://github.com/golang/go/commit/83b4a5db240960720e51b7d5a6da1f399bd868ee%20%28go1.24.6%29"
        },
        {
          "url": "https://github.com/golang/go/commit/8a924caaf348fdc366bab906424616b2974ad4e9%20%28go1.23.12%29"
        },
        {
          "url": "https://github.com/golang/go/issues/74831"
        },
        {
          "url": "https://go.dev/cl/693735"
        },
        {
          "url": "https://go.dev/issue/74831"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/x5MKroML2yM"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/x5MKroML2yM/m/5_v-oMjUAgAJ"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-47907.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-20983.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47907"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-3849"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-47907"
        }
      ],
      "published": "2025-08-07T16:15:30+00:00",
      "updated": "2026-06-17T09:28:49+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-47911",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.",
      "recommendation": "Upgrade golang.org/x/net to version 0.45.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-47911"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-47911"
        },
        {
          "url": "https://github.com/golang/go/issues/75682"
        },
        {
          "url": "https://github.com/golang/vulndb/issues/4440"
        },
        {
          "url": "https://go.dev/cl/709876"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/jnQcOYpiR2c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47911"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4440"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8089-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8089-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8089-3"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8900-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-47911"
        }
      ],
      "published": "2026-02-05T18:16:09+00:00",
      "updated": "2026-06-17T09:28:50+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/net@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2025-47912",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "description": "The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: \"http://[::1]/\". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement.",
      "recommendation": "Upgrade stdlib to version 1.24.8, 1.25.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-47912"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/10/08/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-47912"
        },
        {
          "url": "https://go.dev/cl/709857"
        },
        {
          "url": "https://go.dev/issue/75678"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47912"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-4010"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-47912"
        }
      ],
      "published": "2025-10-29T23:16:18+00:00",
      "updated": "2026-10-08T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-47913",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        617
      ],
      "description": "SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.43.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-47913"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:0470"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-47913"
        },
        {
          "url": "https://bugzilla.redhat.com/2414943"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2414943"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47913"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-0470.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:0470"
        },
        {
          "url": "https://github.com/advisories/GHSA-56w8-48fp-6mgv"
        },
        {
          "url": "https://github.com/advisories/GHSA-hcg3-q754-cr77"
        },
        {
          "url": "https://go-review.googlesource.com/c/crypto/+/700295"
        },
        {
          "url": "https://go.dev/cl/700295"
        },
        {
          "url": "https://go.dev/issue/75178"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-47913.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-0753.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47913"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-4116"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8519-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-47913"
        }
      ],
      "published": "2025-11-13T22:15:51+00:00",
      "updated": "2026-06-17T09:28:50+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2025-47914",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        125
      ],
      "description": "SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.45.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-47914"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-47914"
        },
        {
          "url": "https://go.dev/cl/721960"
        },
        {
          "url": "https://go.dev/issue/76364"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/w-oX3UxNcZA"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47914"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-4135"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-47914"
        }
      ],
      "published": "2025-11-19T21:15:50+00:00",
      "updated": "2026-06-17T09:28:50+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2025-54410",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        909
      ],
      "description": "Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulnerability affects Moby releases before 28.0.0. When firewalld reloads, Docker fails to re-create iptables rules that isolate bridge networks, allowing any container to access all ports on any other container across different bridge networks on the same host. This breaks network segmentation between containers that should be isolated, creating significant risk in multi-tenant environments. Only containers in --internal networks remain protected.\nWorkarounds include reloading firewalld and either restarting the docker daemon, re-creating bridge networks, or using rootless mode. Maintainers anticipate a fix for this issue in version 25.0.13.",
      "recommendation": "Upgrade github.com/docker/docker to version 25.0.13, 28.0.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-54410"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-54410"
        },
        {
          "url": "https://firewalld.org/documentation/howto/reload-firewalld.html"
        },
        {
          "url": "https://github.com/moby/moby"
        },
        {
          "url": "https://github.com/moby/moby/pull/49443"
        },
        {
          "url": "https://github.com/moby/moby/pull/49728"
        },
        {
          "url": "https://github.com/moby/moby/security/advisories/GHSA-4vq8-7jfc-9cvp"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-54410"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-54410"
        }
      ],
      "published": "2025-07-30T14:15:28+00:00",
      "updated": "2026-06-17T09:40:02+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible"
        }
      ]
    },
    {
      "id": "CVE-2025-58181",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        770
      ],
      "description": "SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.45.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-58181"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-58181"
        },
        {
          "url": "https://github.com/golang/crypto/commit/e79546e28b85ea53dd37afe1c4102746ef553b9c"
        },
        {
          "url": "https://github.com/golang/go/issues/76363"
        },
        {
          "url": "https://go.dev/cl/721961"
        },
        {
          "url": "https://go.dev/issue/76363"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/w-oX3UxNcZA"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/w-oX3UxNcZA?pli=1"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58181"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-4134"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7956-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-58181"
        }
      ],
      "published": "2025-11-19T21:15:50+00:00",
      "updated": "2026-06-17T09:44:01+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2025-58183",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "description": "tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.",
      "recommendation": "Upgrade stdlib to version 1.24.8, 1.25.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-58183"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/10/08/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1381"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3122"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-58183"
        },
        {
          "url": "https://bugzilla.redhat.com/2407258"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2407258"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-58183"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1381.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1381"
        },
        {
          "url": "https://go.dev/cl/709861"
        },
        {
          "url": "https://go.dev/issue/75677"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-58183.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50076.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58183"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-4014"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-58183"
        }
      ],
      "published": "2025-10-29T23:16:19+00:00",
      "updated": "2026-10-08T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-58185",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.",
      "recommendation": "Upgrade stdlib to version 1.24.8, 1.25.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-58185"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/10/08/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-58185"
        },
        {
          "url": "https://github.com/golang/go/commit/8709a41d5ef7321f486a1857f189c3fee20e8edd"
        },
        {
          "url": "https://go.dev/cl/709856"
        },
        {
          "url": "https://go.dev/issue/75671"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58185"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-4011"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-58185"
        }
      ],
      "published": "2025-10-29T23:16:19+00:00",
      "updated": "2026-10-08T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-58186",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "description": "Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as \"a=;\", an attacker can make an HTTP server allocate a large amount of structs, causing large memory consumption.",
      "recommendation": "Upgrade stdlib to version 1.24.8, 1.25.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-58186"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/10/08/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-58186"
        },
        {
          "url": "https://go.dev/cl/709855"
        },
        {
          "url": "https://go.dev/issue/75672"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58186"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-4012"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-58186"
        }
      ],
      "published": "2025-10-29T23:16:19+00:00",
      "updated": "2026-06-17T09:44:01+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-58187",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        407
      ],
      "description": "Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains.",
      "recommendation": "Upgrade stdlib to version 1.24.9, 1.25.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-58187"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/10/08/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-58187"
        },
        {
          "url": "https://github.com/golang/go/commit/3fc4c79fdbb17b9b29ea9f8c29dd780df075d4c4"
        },
        {
          "url": "https://go.dev/cl/709854"
        },
        {
          "url": "https://go.dev/issue/75681"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58187"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-4007"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-58187"
        }
      ],
      "published": "2025-10-29T23:16:19+00:00",
      "updated": "2026-10-08T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-58188",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        295
      ],
      "description": "Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.",
      "recommendation": "Upgrade stdlib to version 1.24.8, 1.25.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-58188"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/10/08/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-58188"
        },
        {
          "url": "https://go.dev/cl/709853"
        },
        {
          "url": "https://go.dev/issue/75675"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58188"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-4013"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-58188"
        }
      ],
      "published": "2025-10-29T23:16:19+00:00",
      "updated": "2026-10-08T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-58189",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        532
      ],
      "description": "When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.",
      "recommendation": "Upgrade stdlib to version 1.24.8, 1.25.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-58189"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/10/08/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-58189"
        },
        {
          "url": "https://go.dev/cl/707776"
        },
        {
          "url": "https://go.dev/issue/75652"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58189"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-4008"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-58189"
        }
      ],
      "published": "2025-10-29T23:16:19+00:00",
      "updated": "2026-10-08T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-58190",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        835
      ],
      "description": "The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.",
      "recommendation": "Upgrade golang.org/x/net to version 0.45.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-58190"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-58190"
        },
        {
          "url": "https://github.com/golang/go/issues/70179"
        },
        {
          "url": "https://github.com/golang/vulndb/issues/4441"
        },
        {
          "url": "https://go.dev/cl/709875"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/jnQcOYpiR2c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58190"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4441"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8089-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8089-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8089-3"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8900-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-58190"
        }
      ],
      "published": "2026-02-05T18:16:10+00:00",
      "updated": "2026-06-17T09:44:02+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/net@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2025-61723",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        770
      ],
      "description": "The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM inputs.",
      "recommendation": "Upgrade stdlib to version 1.24.8, 1.25.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-61723"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/10/08/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-61723"
        },
        {
          "url": "https://github.com/golang/go/commit/5ce8cd16f3859ec5ac4106ad8ec15d6236f4501b"
        },
        {
          "url": "https://go.dev/cl/709858"
        },
        {
          "url": "https://go.dev/issue/75676"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61723"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-4009"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-61723"
        }
      ],
      "published": "2025-10-29T23:16:19+00:00",
      "updated": "2026-10-08T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ]
    },
    {
      "id": "CVE-2025-61724",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        770
      ],
      "description": "The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption.",
      "recommendation": "Upgrade stdlib to version 1.24.8, 1.25.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-61724"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/10/08/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-61724"
        },
        {
          "url": "https://go.dev/cl/709859"
        },
        {
          "url": "https://go.dev/issue/75716"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61724"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-4015"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-61724"
        }
      ],
      "published": "2025-10-29T23:16:20+00:00",
      "updated": "2026-10-08T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-61725",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "description": "The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.",
      "recommendation": "Upgrade stdlib to version 1.24.8, 1.25.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-61725"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/10/08/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-61725"
        },
        {
          "url": "https://go.dev/cl/709860"
        },
        {
          "url": "https://go.dev/issue/75680"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61725"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-4006"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-61725"
        }
      ],
      "published": "2025-10-29T23:16:20+00:00",
      "updated": "2026-10-08T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ]
    },
    {
      "id": "CVE-2025-61726",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        770
      ],
      "description": "The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.",
      "recommendation": "Upgrade stdlib to version 1.24.12, 1.25.6",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-61726"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10096"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10104"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10184"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10225"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10250"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11408"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11414"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11747"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11749"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:12028"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:12029"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:12030"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:12031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:12032"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:12033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:12279"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:12282"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13542"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13548"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13571"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:14100"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:14774"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:14868"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:14879"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:15091"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:15984"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16102"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16696"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17040"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17084"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17446"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17460"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17463"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17468"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17595"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17598"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18913"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19013"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19375"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19634"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19712"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20041"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21017"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21657"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21691"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22450"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22627"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22714"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22937"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23228"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23361"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24977"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25089"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25127"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25248"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25250"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25251"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25252"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25253"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26420"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26527"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26541"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26636"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:2681"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:2706"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:2708"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:2709"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:2754"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28047"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:2844"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28441"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28886"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28961"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:2914"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:2920"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3035"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3040"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3089"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3092"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3184"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3186"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3187"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3188"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3192"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3193"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3291"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3296"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3297"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3298"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3336"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3337"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3340"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3341"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3343"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3391"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3416"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3427"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3459"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3468"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3469"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3471"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3472"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3473"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3489"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3506"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3556"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3559"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3668"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3669"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36873"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36882"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3699"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3713"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37275"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3752"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3753"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3782"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3812"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3813"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3814"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3815"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3816"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3817"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3818"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3821"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3822"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3831"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3833"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3835"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3836"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3838"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3839"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3840"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3841"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3843"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3854"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3855"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3856"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3864"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3869"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3874"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3875"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3879"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3880"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3884"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3898"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3905"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3906"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3929"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3931"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3932"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3958"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3959"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3960"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3970"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3971"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3972"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3973"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3974"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3977"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39810"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3985"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40924"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4164"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4166"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4170"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4174"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4177"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41941"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4211"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4220"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4256"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4264"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4267"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4270"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4276"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4434"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4460"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4466"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4467"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4498"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4500"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4510"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4511"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4672"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46903"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4753"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4892"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4901"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4907"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4939"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4942"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4943"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4952"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49944"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5030"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5076"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5077"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5079"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5110"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51288"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5129"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5130"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5131"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5145"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5168"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5327"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5394"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5439"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5444"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5447"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5452"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5461"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5463"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5533"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5544"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5549"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5636"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56366"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56431"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5645"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5649"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5665"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57013"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5807"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5851"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5852"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5853"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5948"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5950"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5952"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5968"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6184"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6192"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6226"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6251"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6277"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6278"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6428"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6429"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6497"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6554"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6564"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6567"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6568"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66401"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7249"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7291"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7385"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7676"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7854"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7942"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8167"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8218"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8229"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8337"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8338"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8431"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8433"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8483"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9097"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9098"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9108"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9109"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9848"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-61726"
        },
        {
          "url": "https://bugzilla.redhat.com/2434432"
        },
        {
          "url": "https://bugzilla.redhat.com/2437111"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2434432"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2437111"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-4177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:4177"
        },
        {
          "url": "https://go.dev/cl/736712"
        },
        {
          "url": "https://go.dev/issue/77101"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-61726.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-5146.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61726"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4341"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-61726"
        }
      ],
      "published": "2026-01-28T20:16:09+00:00",
      "updated": "2026-09-17T12:17:11+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-61727",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        295
      ],
      "description": "An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.",
      "recommendation": "Upgrade stdlib to version 1.24.11, 1.25.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-61727"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-61727"
        },
        {
          "url": "https://go.dev/cl/723900"
        },
        {
          "url": "https://go.dev/issue/76442"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/8FJoBkPddm4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61727"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-4175"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-61727"
        }
      ],
      "published": "2025-12-03T20:16:25+00:00",
      "updated": "2026-06-17T09:50:48+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-61728",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        770
      ],
      "description": "archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.",
      "recommendation": "Upgrade stdlib to version 1.24.12, 1.25.6",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-61728"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/15/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3753"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-61728"
        },
        {
          "url": "https://bugzilla.redhat.com/2418462"
        },
        {
          "url": "https://bugzilla.redhat.com/2434431"
        },
        {
          "url": "https://bugzilla.redhat.com/2434432"
        },
        {
          "url": "https://bugzilla.redhat.com/2437111"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418462"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2434431"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2434432"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2437111"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61728"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61729"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-3753.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:3753"
        },
        {
          "url": "https://go.dev/cl/736713"
        },
        {
          "url": "https://go.dev/issue/77102"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-61728.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-4672.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61728"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4342"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-61728"
        }
      ],
      "published": "2026-01-28T20:16:09+00:00",
      "updated": "2026-06-17T09:50:48+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-61729",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        295
      ],
      "description": "Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.",
      "recommendation": "Upgrade stdlib to version 1.24.11, 1.25.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-61729"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:3928"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-61729"
        },
        {
          "url": "https://bugzilla.redhat.com/2418462"
        },
        {
          "url": "https://bugzilla.redhat.com/2434432"
        },
        {
          "url": "https://bugzilla.redhat.com/2437111"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418462"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2434432"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2437111"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61729"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-3928.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:3928"
        },
        {
          "url": "https://go.dev/cl/725920"
        },
        {
          "url": "https://go.dev/issue/76445"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/8FJoBkPddm4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-61729.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-5146.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61729"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2025-4155"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-61729"
        }
      ],
      "published": "2025-12-02T19:15:51+00:00",
      "updated": "2026-06-17T09:50:48+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-61730",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "description": "During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake.",
      "recommendation": "Upgrade stdlib to version 1.24.12, 1.25.6",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-61730"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-61730"
        },
        {
          "url": "https://go.dev/cl/724120"
        },
        {
          "url": "https://go.dev/issue/76443"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61730"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4340"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-61730"
        }
      ],
      "published": "2026-01-28T20:16:09+00:00",
      "updated": "2026-06-17T09:50:48+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-68121",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 10,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        295
      ],
      "description": "During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.",
      "recommendation": "Upgrade stdlib to version 1.24.13, 1.25.7, 1.26.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-68121"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:4177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-68121"
        },
        {
          "url": "https://bugzilla.redhat.com/2434432"
        },
        {
          "url": "https://bugzilla.redhat.com/2437111"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2434432"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2437111"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-4177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:4177"
        },
        {
          "url": "https://github.com/golang/go/issues/77113"
        },
        {
          "url": "https://go.dev/cl/737700"
        },
        {
          "url": "https://go.dev/issue/77217"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/K09ubi9FQFk"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-68121.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-5146.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68121"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4337"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68121"
        }
      ],
      "published": "2026-02-05T18:16:10+00:00",
      "updated": "2026-06-17T09:58:33+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-8556",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        1287
      ],
      "description": "A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.",
      "recommendation": "Upgrade github.com/cloudflare/circl to version 1.6.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-8556"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-8556"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2371624"
        },
        {
          "url": "https://github.com/cloudflare/circl"
        },
        {
          "url": "https://github.com/cloudflare/circl/security/advisories/GHSA-2x5j-vhc8-9cwm"
        },
        {
          "url": "https://github.com/cloudflare/circl/tree/v1.6.1"
        },
        {
          "url": "https://news.ycombinator.com/item?id=45669593"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-8556"
        },
        {
          "url": "https://www.botanica.software/blog/cryptographic-issues-in-cloudflares-circl-fourq-implementation"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-8556"
        }
      ],
      "published": "2025-08-06T09:15:28+00:00",
      "updated": "2026-06-17T10:07:13+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/cloudflare/circl@v1.3.7",
          "versions": [
            {
              "version": "v1.3.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/cloudflare/circl@v1.3.7",
          "versions": [
            {
              "version": "v1.3.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/cloudflare/circl@v1.3.7",
          "versions": [
            {
              "version": "v1.3.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/cloudflare/circl@v1.3.7",
          "versions": [
            {
              "version": "v1.3.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/cloudflare/circl@v1.3.7",
          "versions": [
            {
              "version": "v1.3.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/cloudflare/circl@v1.3.7"
        }
      ]
    },
    {
      "id": "CVE-2026-1229",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        682
      ],
      "description": "The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas.\nECDH and ECDSA signing relying on this curve are not affected.\n\nThe bug was fixed in  v1.6.3 https://github.com/cloudflare/circl/releases/tag/v1.6.3 .",
      "recommendation": "Upgrade github.com/cloudflare/circl to version 1.6.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1229"
        },
        {
          "url": "https://github.com/cloudflare/circl"
        },
        {
          "url": "https://github.com/cloudflare/circl/pull/583"
        },
        {
          "url": "https://github.com/cloudflare/circl/releases/tag/v1.6.3"
        },
        {
          "url": "https://github.com/cloudflare/circl/security/advisories/GHSA-q9hv-hpm4-hj6x"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1229"
        }
      ],
      "published": "2026-02-24T08:16:28+00:00",
      "updated": "2026-06-17T10:15:21+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/cloudflare/circl@v1.3.7",
          "versions": [
            {
              "version": "v1.3.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/cloudflare/circl@v1.3.7",
          "versions": [
            {
              "version": "v1.3.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/cloudflare/circl@v1.3.7",
          "versions": [
            {
              "version": "v1.3.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/cloudflare/circl@v1.3.7",
          "versions": [
            {
              "version": "v1.3.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/cloudflare/circl@v1.3.7",
          "versions": [
            {
              "version": "v1.3.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/cloudflare/circl@v1.3.7"
        }
      ]
    },
    {
      "id": "CVE-2026-25679",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        425,
        1286
      ],
      "description": "url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.",
      "recommendation": "Upgrade stdlib to version 1.25.8, 1.26.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-25679"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10065"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10125"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10133"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10140"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10141"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10158"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10169"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10175"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10184"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10225"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10250"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10701"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10712"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10929"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11217"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11375"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11412"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11413"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11686"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11688"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11747"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11749"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11768"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11800"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11856"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11916"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11996"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:12028"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:12029"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:12030"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:12031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:12032"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:12033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:12282"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13508"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13545"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13642"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13643"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13671"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13791"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13829"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:14020"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:14100"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:14774"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:14868"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:14879"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:15091"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16102"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16696"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16874"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16875"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17040"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17084"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17598"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19017"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19026"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19027"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19032"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19049"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19055"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19126"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19128"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19133"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19135"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19181"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19184"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19185"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19207"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19350"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19353"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19375"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19634"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19719"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19720"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19721"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19750"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20041"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20088"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20581"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20582"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20584"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20889"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21017"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21655"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21657"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21691"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21696"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21769"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22347"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22423"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22450"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22627"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22714"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22733"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22862"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22937"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23228"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23345"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24386"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24853"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25043"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25127"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25180"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25248"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25250"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25251"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25252"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25253"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26445"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26527"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26541"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26568"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26585"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26636"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:27076"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28047"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28441"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28886"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28893"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28961"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29035"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29195"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29455"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29702"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29703"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29854"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33722"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34097"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34365"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36317"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39810"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49944"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5110"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51288"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52389"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52390"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52391"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54191"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5549"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56785"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56852"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56910"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57482"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5941"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5942"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5943"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:5944"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59830"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6341"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6344"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6382"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6383"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6388"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6564"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65838"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66401"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6720"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6802"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:6949"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7005"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7009"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7011"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7259"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7291"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7315"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7328"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7385"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7665"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7669"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7674"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7833"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7834"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7876"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7877"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7878"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7879"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7883"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7992"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8167"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8314"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8322"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8324"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8337"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8338"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8433"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8434"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8456"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8483"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8484"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8490"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8491"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8493"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8840"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8841"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8842"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8845"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8847"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8848"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8849"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8851"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8852"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8853"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8855"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8856"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8860"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8877"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8878"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8879"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8881"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8882"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8931"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8949"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9043"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9044"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9090"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9093"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9094"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9097"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9098"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9108"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9109"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9385"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9434"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9436"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9439"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9448"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9453"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9461"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9695"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9742"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9872"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-25679"
        },
        {
          "url": "https://bugzilla.redhat.com/2445356"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445356"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-9044.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:9044"
        },
        {
          "url": "https://go.dev/cl/752180"
        },
        {
          "url": "https://go.dev/issue/77578"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-25679.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-9044.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25679"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4601"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25679"
        }
      ],
      "published": "2026-03-06T22:16:00+00:00",
      "updated": "2026-09-18T13:17:30+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-25680",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.",
      "recommendation": "Upgrade golang.org/x/net to version 0.55.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-25680"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-25680"
        },
        {
          "url": "https://go.dev/cl/781702"
        },
        {
          "url": "https://go.dev/issue/79573"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5028"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25680"
        }
      ],
      "published": "2026-05-22T16:16:19+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/net@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-25681",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        1021
      ],
      "description": "Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.",
      "recommendation": "Upgrade golang.org/x/net to version 0.55.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-25681"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69293"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-25681"
        },
        {
          "url": "https://bugzilla.redhat.com/2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/2480762"
        },
        {
          "url": "https://bugzilla.redhat.com/2484830"
        },
        {
          "url": "https://bugzilla.redhat.com/2493622"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480762"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484830"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493622"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27136"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41178"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55677"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-69293.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69293"
        },
        {
          "url": "https://go.dev/cl/781703"
        },
        {
          "url": "https://go.dev/issue/79574"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-25681.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67139-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5029"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25681"
        }
      ],
      "published": "2026-05-22T16:16:19+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/net@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-25934",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        354
      ],
      "description": "go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-git potentially consuming corrupted files, which would likely result in unexpected errors such as object not found. For context, clients fetch packfiles from upstream Git servers. Those files contain a checksum of their contents, so that clients can perform integrity checks before consuming it. The pack indexes (.idx) are generated locally by go-git, or the git cli, when new .pack files are received and processed. The integrity checks for both files were not being verified correctly. This vulnerability is fixed in 5.16.5.",
      "recommendation": "Upgrade github.com/go-git/go-git/v5 to version 5.16.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-25934"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-25934"
        },
        {
          "url": "https://github.com/go-git/go-git"
        },
        {
          "url": "https://github.com/go-git/go-git/releases/tag/v5.16.5"
        },
        {
          "url": "https://github.com/go-git/go-git/security/advisories/GHSA-37cx-329c-33x3"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25934"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8088-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25934"
        }
      ],
      "published": "2026-02-09T23:16:05+00:00",
      "updated": "2026-06-17T10:25:27+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/go-git/go-git/v5@v5.12.0"
        }
      ]
    },
    {
      "id": "CVE-2026-27136",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        1021
      ],
      "description": "Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.",
      "recommendation": "Upgrade golang.org/x/net to version 0.55.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27136"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69293"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27136"
        },
        {
          "url": "https://bugzilla.redhat.com/2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/2480762"
        },
        {
          "url": "https://bugzilla.redhat.com/2484830"
        },
        {
          "url": "https://bugzilla.redhat.com/2493622"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480762"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484830"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493622"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27136"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41178"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55677"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-69293.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69293"
        },
        {
          "url": "https://go.dev/cl/781685"
        },
        {
          "url": "https://go.dev/issue/79575"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-27136.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67139-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5030"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27136"
        }
      ],
      "published": "2026-05-22T16:16:20+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/net@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-27139",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        22
      ],
      "description": "On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.",
      "recommendation": "Upgrade stdlib to version 1.25.8, 1.26.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27139"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27139"
        },
        {
          "url": "https://go.dev/cl/749480"
        },
        {
          "url": "https://go.dev/issue/77827"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27139"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4602"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27139"
        }
      ],
      "published": "2026-03-06T22:16:01+00:00",
      "updated": "2026-06-17T10:26:44+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-27142",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        79
      ],
      "description": "Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value \"refresh\". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow \"url=\" by setting htmlmetacontenturlescape=0.",
      "recommendation": "Upgrade stdlib to version 1.25.8, 1.26.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27142"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27142"
        },
        {
          "url": "https://go.dev/cl/752081"
        },
        {
          "url": "https://go.dev/issue/77954"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27142"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4603"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27142"
        }
      ],
      "published": "2026-03-06T22:16:01+00:00",
      "updated": "2026-06-17T10:26:44+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-27145",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        606
      ],
      "description": "(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.",
      "recommendation": "Upgrade stdlib to version 1.25.11, 1.26.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27145"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23264"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29980"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33574"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34357"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34359"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35832"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36317"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38995"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39005"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39573"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39879"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41030"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42043"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42047"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42049"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42050"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42051"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42079"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42080"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42082"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42142"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42240"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42946"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44622"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46394"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47737"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49702"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49703"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49705"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49712"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49729"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49744"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49765"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49770"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50205"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51057"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51187"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52946"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53412"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53413"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53415"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53416"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53530"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54168"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54401"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54427"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54432"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54441"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54500"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54525"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54603"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55899"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57482"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57488"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57649"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59556"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59557"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59558"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59559"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59579"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59593"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60025"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60315"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60354"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60386"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60388"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60390"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60391"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61253"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61314"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63016"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:68334"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:68335"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27145"
        },
        {
          "url": "https://bugzilla.redhat.com/2445356"
        },
        {
          "url": "https://bugzilla.redhat.com/2484207"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445356"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484207"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-36317.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:36317"
        },
        {
          "url": "https://go.dev/cl/783621"
        },
        {
          "url": "https://go.dev/issue/79694"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-27145.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-53416.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5037"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27145"
        }
      ],
      "published": "2026-06-02T23:16:35+00:00",
      "updated": "2026-09-18T13:17:43+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-32280",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        770
      ],
      "description": "During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.",
      "recommendation": "Upgrade stdlib to version 1.25.9, 1.26.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32280"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10217"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10219"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10704"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11507"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11514"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11688"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13545"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13791"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13826"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13829"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:14020"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:14162"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:14200"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:14391"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:15980"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16021"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16024"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16101"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16477"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16505"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16508"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16532"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16534"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16535"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16537"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16542"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16874"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16875"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17084"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18027"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18032"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19133"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19135"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19144"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19350"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19353"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19375"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19450"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19550"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19634"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19714"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19715"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19719"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19720"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19721"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19722"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19750"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19839"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20556"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20569"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20570"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20571"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20607"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20608"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20609"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20889"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21017"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21338"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21655"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21769"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21772"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22130"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22141"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22258"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22260"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22268"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22309"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22347"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22415"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22422"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22465"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22485"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22709"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22713"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22840"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22862"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22958"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22959"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22960"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22961"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22962"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23102"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23103"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23244"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23345"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23361"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24337"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24359"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24478"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24716"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24761"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24762"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24853"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24977"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25089"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25127"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25180"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25248"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25250"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25251"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25252"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25253"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26447"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26568"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26571"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26585"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26636"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:27076"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28047"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28074"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28196"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28198"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28441"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28886"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28961"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29035"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29195"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29455"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29702"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29703"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29854"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33722"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34097"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34192"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34196"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34197"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34365"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36625"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39810"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39894"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42043"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42047"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42049"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42050"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42051"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47712"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47714"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47716"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47719"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47721"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47722"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47910"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47952"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48790"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49509"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49526"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49600"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49838"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49944"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51288"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54191"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54603"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56785"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56789"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56852"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56855"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56910"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56912"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56913"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57409"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57482"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57488"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59830"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59833"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59834"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61685"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61906"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61907"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65534"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65838"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65886"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66401"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:68504"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9385"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32280"
        },
        {
          "url": "https://bugzilla.redhat.com/2456333"
        },
        {
          "url": "https://bugzilla.redhat.com/2456339"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456333"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456339"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484204"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515840"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-49838.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:65886"
        },
        {
          "url": "https://go.dev/cl/758320"
        },
        {
          "url": "https://go.dev/issue/78282"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-32280.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-65886-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32280"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4947"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32280"
        }
      ],
      "published": "2026-04-08T02:16:03+00:00",
      "updated": "2026-09-18T13:17:45+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-32281",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        295
      ],
      "description": "Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.",
      "recommendation": "Upgrade stdlib to version 1.25.9, 1.26.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32281"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49838"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65886"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32281"
        },
        {
          "url": "https://bugzilla.redhat.com/2456333"
        },
        {
          "url": "https://bugzilla.redhat.com/2456339"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456333"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456339"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484204"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515840"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-49838.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:65886"
        },
        {
          "url": "https://go.dev/cl/758061"
        },
        {
          "url": "https://go.dev/issue/78281"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-32281.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67148-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32281"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4946"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32281"
        }
      ],
      "published": "2026-04-08T02:16:03+00:00",
      "updated": "2026-07-25T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-32282",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        59
      ],
      "description": "On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.",
      "recommendation": "Upgrade stdlib to version 1.25.9, 1.26.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32282"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19353"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23228"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32282"
        },
        {
          "url": "https://bugzilla.redhat.com/2445356"
        },
        {
          "url": "https://bugzilla.redhat.com/2449833"
        },
        {
          "url": "https://bugzilla.redhat.com/2455470"
        },
        {
          "url": "https://bugzilla.redhat.com/2456333"
        },
        {
          "url": "https://bugzilla.redhat.com/2456335"
        },
        {
          "url": "https://bugzilla.redhat.com/2456336"
        },
        {
          "url": "https://bugzilla.redhat.com/2456338"
        },
        {
          "url": "https://bugzilla.redhat.com/2456339"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2434432"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2437111"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445345"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445356"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449833"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455470"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456336"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456338"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27137"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33186"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34986"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19353.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:23228"
        },
        {
          "url": "https://go.dev/cl/763761"
        },
        {
          "url": "https://go.dev/issue/78293"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-32282.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-48790.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32282"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4864"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32282"
        }
      ],
      "published": "2026-04-08T02:16:03+00:00",
      "updated": "2026-07-25T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-32283",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        770,
        764
      ],
      "description": "If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.",
      "recommendation": "Upgrade stdlib to version 1.25.9, 1.26.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32283"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10217"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10219"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10704"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11507"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11514"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11704"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11711"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11712"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11863"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11881"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:14162"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:14200"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:14391"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:15980"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16021"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16024"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16101"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16102"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16875"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17075"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17084"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18027"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18032"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19126"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19133"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19134"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19135"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19136"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19137"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19139"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19144"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19156"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19350"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19351"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19352"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19353"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19369"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19450"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19550"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19634"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19714"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19715"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19719"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19720"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19721"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19722"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19750"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19839"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20556"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20569"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20570"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20571"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20607"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20608"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20609"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21769"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22347"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22423"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22450"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22485"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22709"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22713"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22714"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22937"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23102"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23103"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23228"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23345"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24337"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24761"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24762"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25248"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25250"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25251"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25252"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26447"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26571"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26636"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:27076"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28047"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28074"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29035"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29195"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29455"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29703"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33722"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34192"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34196"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34197"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34365"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39810"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47712"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47714"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47716"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47719"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47721"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47722"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47910"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48790"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49509"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49600"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49944"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51288"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54191"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55898"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55900"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55901"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55902"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55903"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56910"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57409"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57801"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57802"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65126"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65343"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65514"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66084"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66401"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66523"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:68504"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7291"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7385"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32283"
        },
        {
          "url": "https://bugzilla.redhat.com/2445356"
        },
        {
          "url": "https://bugzilla.redhat.com/2456333"
        },
        {
          "url": "https://bugzilla.redhat.com/2456338"
        },
        {
          "url": "https://bugzilla.redhat.com/2456339"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445356"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456333"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456338"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456339"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-29703.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:29703"
        },
        {
          "url": "https://go.dev/cl/763767"
        },
        {
          "url": "https://go.dev/issue/78334"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-32283.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-48790.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32283"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4870"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32283"
        }
      ],
      "published": "2026-04-08T02:16:03+00:00",
      "updated": "2026-09-18T13:17:48+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-32288",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        770
      ],
      "description": "tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the \"old GNU sparse map\" format.",
      "recommendation": "Upgrade stdlib to version 1.25.9, 1.26.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32288"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32288"
        },
        {
          "url": "https://go.dev/cl/763766"
        },
        {
          "url": "https://go.dev/issue/78301"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32288"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4869"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32288"
        }
      ],
      "published": "2026-04-08T02:16:03+00:00",
      "updated": "2026-07-25T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-32289",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        79
      ],
      "description": "Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.",
      "recommendation": "Upgrade stdlib to version 1.25.9, 1.26.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32289"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32289"
        },
        {
          "url": "https://go.dev/cl/763762"
        },
        {
          "url": "https://go.dev/issue/78331"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32289"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4865"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32289"
        }
      ],
      "published": "2026-04-08T02:16:03+00:00",
      "updated": "2026-07-25T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-33762",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        129
      ],
      "description": "go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git\u2019s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded path name. A maliciously crafted index file can trigger an out-of-bounds slice operation, resulting in a runtime panic during normal index parsing. This issue only affects Git index format version 4. Earlier formats (go-git supports only v2 and v3) are not vulnerable to this issue. This issue has been patched in version 5.17.1.",
      "recommendation": "Upgrade github.com/go-git/go-git/v5 to version 5.17.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33762"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33762"
        },
        {
          "url": "https://github.com/go-git/go-git"
        },
        {
          "url": "https://github.com/go-git/go-git/releases/tag/v5.17.1"
        },
        {
          "url": "https://github.com/go-git/go-git/security/advisories/GHSA-gm2x-2g9h-ccm8"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33762"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33762"
        }
      ],
      "published": "2026-03-31T15:16:15+00:00",
      "updated": "2026-07-24T21:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/go-git/go-git/v5@v5.12.0"
        }
      ]
    },
    {
      "id": "CVE-2026-33811",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        415,
        1341
      ],
      "description": "When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.",
      "recommendation": "Upgrade stdlib to version 1.25.10, 1.26.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33811"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22112"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22120"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22121"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23264"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33120"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33123"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33142"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33574"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34357"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34359"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34364"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35832"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35993"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35994"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35995"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36207"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36617"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36625"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36776"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38504"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39266"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39272"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39573"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39810"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40119"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41030"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41055"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42043"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42047"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42048"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42049"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42050"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42051"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42079"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42082"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42240"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42852"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42946"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44622"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46885"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47952"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49702"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49703"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49712"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50205"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50300"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50336"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50843"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51057"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51187"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51341"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53412"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53413"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53415"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53530"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54168"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54191"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54274"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54283"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54284"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54285"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54441"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54500"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54552"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54556"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54584"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54602"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54603"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56340"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56785"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56789"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56790"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56852"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56855"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56910"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56912"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56913"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57191"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57482"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57488"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57649"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59467"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59559"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60025"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60302"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61253"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61313"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65126"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65534"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65886"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67319"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33811"
        },
        {
          "url": "https://bugzilla.redhat.com/2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456333"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456339"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484204"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515840"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-39319.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:65886"
        },
        {
          "url": "https://go.dev/cl/767860"
        },
        {
          "url": "https://go.dev/issue/78803"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/qcCIEXso47M"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-33811.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-65886-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4981"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33811"
        }
      ],
      "published": "2026-05-07T20:16:42+00:00",
      "updated": "2026-09-18T13:17:57+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-33814",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        835,
        606
      ],
      "description": "When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.",
      "recommendation": "Upgrade golang.org/x/net to version 0.53.0; Upgrade stdlib to version 1.25.10, 1.26.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33814"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22112"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22120"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22121"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23264"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33120"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33123"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33142"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49702"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49712"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50205"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54274"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54283"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54284"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54285"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56854"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56912"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57191"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57365"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57367"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57408"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57545"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57649"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57845"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59833"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60023"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60025"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60441"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60442"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60446"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60447"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60454"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60477"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60478"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60668"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61253"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62410"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62550"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62551"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63046"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63047"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63048"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63050"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63091"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63096"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63097"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63103"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63104"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63636"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63637"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63639"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65126"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66350"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33814"
        },
        {
          "url": "https://bugzilla.redhat.com/2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467810"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467811"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467813"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467823"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467825"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467826"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467827"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33814"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39817"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39819"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39823"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39825"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39826"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39836"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42501"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-22112.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:22121"
        },
        {
          "url": "https://github.com/golang/go/issues/78476"
        },
        {
          "url": "https://go-review.googlesource.com/c/go/+/761581"
        },
        {
          "url": "https://go-review.googlesource.com/c/net/+/761640"
        },
        {
          "url": "https://go.dev/cl/761581"
        },
        {
          "url": "https://go.dev/cl/761640"
        },
        {
          "url": "https://go.dev/issue/78476"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/qcCIEXso47M"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-33814.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-22121.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4918"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8430-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8471-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8472-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8473-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33814"
        }
      ],
      "published": "2026-05-07T20:16:42+00:00",
      "updated": "2026-09-18T13:17:59+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/net@v0.25.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-33818",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33818"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70641"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33818"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11395"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-70641.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70641"
        },
        {
          "url": "https://go.dev/cl/814980"
        },
        {
          "url": "https://go.dev/issue/80405"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-33818.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33818"
        }
      ],
      "published": "2026-08-13T22:17:19+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-33997",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        193,
        266
      ],
      "description": "Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrectly accept a privilege set that differs from the one approved by the user. Plugins that request exactly one privilege are also affected, because no comparison is performed at all. This issue has been patched in version 29.3.1.",
      "recommendation": "Upgrade github.com/docker/docker to version 29.3.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33997"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21769"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22347"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23345"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33997"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2453277"
        },
        {
          "url": "https://docs.docker.com/engine/extend/legacy_plugins"
        },
        {
          "url": "https://github.com/moby/moby"
        },
        {
          "url": "https://github.com/moby/moby/commit/f4d6f25bf0c3fa12d4968320a45685947756a22a"
        },
        {
          "url": "https://github.com/moby/moby/releases/tag/docker-v29.3.1"
        },
        {
          "url": "https://github.com/moby/moby/security/advisories/GHSA-pxq6-2prw-chj9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33997"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33997.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33997"
        }
      ],
      "published": "2026-03-31T03:15:57+00:00",
      "updated": "2026-09-09T13:19:32+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible"
        }
      ]
    },
    {
      "id": "CVE-2026-34165",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        191,
        770
      ],
      "description": "go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, potentially exhausting available memory and resulting in a denial-of-service (DoS) condition. Exploitation requires write access to the local repository's .git directory, it order to create or alter existing .idx files. This issue has been patched in version 5.17.1.",
      "recommendation": "Upgrade github.com/go-git/go-git/v5 to version 5.17.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34165"
        },
        {
          "url": "https://github.com/go-git/go-git"
        },
        {
          "url": "https://github.com/go-git/go-git/releases/tag/v5.17.1"
        },
        {
          "url": "https://github.com/go-git/go-git/security/advisories/GHSA-jhf3-xxhw-2wpp"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34165"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34165"
        }
      ],
      "published": "2026-03-31T15:16:17+00:00",
      "updated": "2026-07-24T21:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/go-git/go-git/v5@v5.12.0"
        }
      ]
    },
    {
      "id": "CVE-2026-34986",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        248,
        131
      ],
      "description": "Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also reachable by calling cipher.KeyUnwrap() directly with any ciphertext parameter less than 16 bytes long, but calling this function directly is less common. Panics can lead to denial of service. This vulnerability is fixed in 4.1.4 and 3.0.5.",
      "recommendation": "Upgrade github.com/go-jose/go-jose/v3 to version 3.0.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34986"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10125"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10130"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10135"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10175"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11070"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11217"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11688"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11856"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11916"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11996"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:12116"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:12277"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:12279"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13791"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13829"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:16696"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17040"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17121"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17123"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17448"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17458"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17459"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17468"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17474"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17550"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17598"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17789"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18584"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18585"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19017"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19099"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19108"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19135"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19173"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19186"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19353"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19375"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19712"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19719"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19720"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19721"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20034"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20041"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20569"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20607"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20609"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20946"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21017"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21703"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21709"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21769"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21931"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21932"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22258"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22260"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22347"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22423"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22450"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22465"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22629"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22714"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22840"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22937"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23228"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23241"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23345"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23361"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24471"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24477"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24479"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24482"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24484"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24853"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24977"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25127"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25187"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25206"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25248"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25250"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25252"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26054"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26568"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26585"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26636"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:27001"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:27004"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:27044"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:27063"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:27856"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28198"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29854"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30650"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:32991"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33722"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34099"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34192"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34196"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34197"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34364"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34794"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35833"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40984"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41941"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41944"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44267"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46885"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47952"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48085"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48676"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48790"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49944"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54602"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56366"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56431"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56968"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57013"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57408"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57487"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57590"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60023"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60444"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60449"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60452"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62260"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62548"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62550"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65838"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65906"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66385"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8490"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8491"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8493"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9385"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9388"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9448"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9453"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34986"
        },
        {
          "url": "https://bugzilla.redhat.com/2445356"
        },
        {
          "url": "https://bugzilla.redhat.com/2449833"
        },
        {
          "url": "https://bugzilla.redhat.com/2455470"
        },
        {
          "url": "https://bugzilla.redhat.com/2456333"
        },
        {
          "url": "https://bugzilla.redhat.com/2456335"
        },
        {
          "url": "https://bugzilla.redhat.com/2456336"
        },
        {
          "url": "https://bugzilla.redhat.com/2456338"
        },
        {
          "url": "https://bugzilla.redhat.com/2456339"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2434432"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2437111"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445345"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445356"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449833"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455470"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456336"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456338"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27137"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33186"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34986"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19353.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:23228"
        },
        {
          "url": "https://github.com/go-jose/go-jose"
        },
        {
          "url": "https://github.com/go-jose/go-jose/security/advisories/GHSA-78h2-9frx-2jm8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-34986.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-48790.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
        },
        {
          "url": "https://pkg.go.dev/github.com/go-jose/go-jose/v4#pkg-constants"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34986.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34986"
        }
      ],
      "published": "2026-04-06T17:17:11+00:00",
      "updated": "2026-09-18T13:18:05+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/go-jose/go-jose/v3@v3.0.3",
          "versions": [
            {
              "version": "v3.0.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-jose/go-jose/v3@v3.0.3",
          "versions": [
            {
              "version": "v3.0.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-jose/go-jose/v3@v3.0.3",
          "versions": [
            {
              "version": "v3.0.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-jose/go-jose/v3@v3.0.3",
          "versions": [
            {
              "version": "v3.0.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-jose/go-jose/v3@v3.0.3",
          "versions": [
            {
              "version": "v3.0.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/go-jose/go-jose/v3@v3.0.3"
        }
      ]
    },
    {
      "id": "CVE-2026-39820",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        770,
        606
      ],
      "description": "Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.",
      "recommendation": "Upgrade stdlib to version 1.25.10, 1.26.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22112"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22120"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22121"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23264"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33120"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33123"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33142"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33574"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34364"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36625"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36754"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47952"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49702"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49712"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50205"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50300"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50336"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50843"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51112"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54274"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54283"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54284"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54285"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54552"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54555"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54583"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54602"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54883"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56340"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56789"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56852"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56854"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57401"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57482"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57487"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57649"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57845"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57914"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59467"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59830"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59833"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60023"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61253"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62260"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62406"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62407"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62753"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62754"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62803"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65116"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65117"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65153"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65335"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65336"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65534"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65838"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65886"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65895"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66016"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66327"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67517"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67974"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67975"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:68334"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:68504"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:68527"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39820"
        },
        {
          "url": "https://bugzilla.redhat.com/2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/2484204"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456333"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456339"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484204"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515840"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-65153.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:65886"
        },
        {
          "url": "https://go.dev/cl/759940"
        },
        {
          "url": "https://go.dev/issue/78566"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/qcCIEXso47M"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39820.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-65895-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4986"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39820"
        }
      ],
      "published": "2026-05-07T20:16:43+00:00",
      "updated": "2026-09-18T13:18:07+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-39821",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        1289
      ],
      "description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".",
      "recommendation": "Upgrade golang.org/x/net to version 0.55.0; Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39821"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23264"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30650"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30853"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30854"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30855"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33155"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33163"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33173"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33183"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33524"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34357"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34359"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34364"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34789"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35826"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35827"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35828"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35829"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35830"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35831"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35993"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35994"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36105"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36167"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36207"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36808"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36883"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37436"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38995"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39005"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39573"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39879"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41030"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41055"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42043"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42047"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42048"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42049"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42050"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42051"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42079"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42080"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42082"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42142"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42240"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42852"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44622"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44624"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47737"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47952"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49702"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49712"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50300"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50843"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51112"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51187"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51341"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52826"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53412"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53413"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53415"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53530"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54191"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54274"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54283"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54284"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54285"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54401"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54441"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54580"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56143"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56223"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56340"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56431"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57541"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57649"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57845"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59549"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59562"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60315"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60354"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61245"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61253"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62549"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63134"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65126"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65153"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65359"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65534"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65851"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65886"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66016"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66350"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66432"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67159"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67517"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:68504"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39821"
        },
        {
          "url": "https://bugzilla.redhat.com/2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/2484204"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456333"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456339"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484204"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515840"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-65153.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:65886"
        },
        {
          "url": "https://go.dev/cl/767220"
        },
        {
          "url": "https://go.dev/issue/78760"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39821.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-66432-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5026"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8416-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8883-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8900-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39821"
        }
      ],
      "published": "2026-05-22T16:16:20+00:00",
      "updated": "2026-09-17T12:18:05+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/net@v0.25.0"
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-39822",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        61
      ],
      "description": "On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root.",
      "recommendation": "Upgrade stdlib to version 1.25.12, 1.26.5, 1.27.0-rc.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39822"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38878"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39822"
        },
        {
          "url": "https://bugzilla.redhat.com/2498152"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498152"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-38878.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:38878"
        },
        {
          "url": "https://go.dev/cl/797880"
        },
        {
          "url": "https://go.dev/issue/79005"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39822.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-38995.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4970"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39822"
        }
      ],
      "published": "2026-07-08T17:17:21+00:00",
      "updated": "2026-09-17T17:10:20+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the Go stdlib flaw is carried by a bundled Go binary (the Confluent CLI / tooling) in the image, not the product's Java runtime, and it is not invoked with attacker-controlled input as part of the product, so the vulnerable code path is not reachable in the product."
      }
    },
    {
      "id": "CVE-2026-39823",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        79
      ],
      "description": "CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS.",
      "recommendation": "Upgrade stdlib to version 1.25.10, 1.26.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39823"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22112"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22121"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39823"
        },
        {
          "url": "https://bugzilla.redhat.com/2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467810"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467811"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467813"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467823"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467825"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467826"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467827"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33814"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39817"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39819"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39823"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39825"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39826"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39836"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42501"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-22112.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:22121"
        },
        {
          "url": "https://go.dev/cl/769920"
        },
        {
          "url": "https://go.dev/issue/78913"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/qcCIEXso47M"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39823.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-22121.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39823"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4982"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39823"
        }
      ],
      "published": "2026-05-07T20:16:43+00:00",
      "updated": "2026-06-17T10:42:38+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-39825",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "description": "ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query \"a1=x&a2=x&...&a10000=x&hidden=y\" can forward the parameter \"hidden=y\" while hiding it from the proxy's Rewrite function.",
      "recommendation": "Upgrade stdlib to version 1.25.10, 1.26.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39825"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22112"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22121"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39825"
        },
        {
          "url": "https://bugzilla.redhat.com/2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467810"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467811"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467813"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467823"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467825"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467826"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467827"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33814"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39817"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39819"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39823"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39825"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39826"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39836"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42501"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-22112.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:22121"
        },
        {
          "url": "https://go.dev/cl/770541"
        },
        {
          "url": "https://go.dev/issue/78948"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/qcCIEXso47M"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39825.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-22121.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39825"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4976"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39825"
        }
      ],
      "published": "2026-05-07T20:16:43+00:00",
      "updated": "2026-06-17T10:42:38+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-39826",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        116
      ],
      "description": "If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block.",
      "recommendation": "Upgrade stdlib to version 1.25.10, 1.26.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39826"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22112"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22121"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39826"
        },
        {
          "url": "https://bugzilla.redhat.com/2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467810"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467811"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467813"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467823"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467825"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467826"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467827"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33814"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39817"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39819"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39823"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39825"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39826"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39836"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42501"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-22112.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:22121"
        },
        {
          "url": "https://go.dev/cl/771180"
        },
        {
          "url": "https://go.dev/issue/78981"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/qcCIEXso47M"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39826.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-22121.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39826"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4980"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39826"
        }
      ],
      "published": "2026-05-07T20:16:43+00:00",
      "updated": "2026-06-17T10:42:38+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-39827",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        924
      ],
      "description": "An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released for garbage collection.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39827"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39827"
        },
        {
          "url": "https://go.dev/cl/781320"
        },
        {
          "url": "https://go.dev/issue/35127"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5016"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39827"
        }
      ],
      "published": "2026-05-22T04:16:21+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-39828",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        295,
        281
      ],
      "description": "When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39828"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36105"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36167"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36207"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36625"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36808"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37268"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37271"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37272"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37278"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37296"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40969"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40972"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40974"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41055"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46885"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46903"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52857"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52910"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57191"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59467"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66521"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39828"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480687"
        },
        {
          "url": "https://go.dev/cl/781621"
        },
        {
          "url": "https://go.dev/issue/79562"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5014"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39828.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39828"
        }
      ],
      "published": "2026-05-22T04:16:22+00:00",
      "updated": "2026-09-11T13:17:51+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-39829",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        347,
        1284
      ],
      "description": "The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39829"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29455"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35833"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36199"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36207"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36625"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36808"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36883"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37072"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37123"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37268"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37271"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37272"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37278"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37296"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40969"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40972"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40974"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41055"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46885"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46903"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47949"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48693"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49944"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52857"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52910"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54400"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54432"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57191"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57365"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57801"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59467"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59559"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59593"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60446"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60454"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60477"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61314"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65126"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65964"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67450"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39829"
        },
        {
          "url": "https://bugzilla.redhat.com/2480680"
        },
        {
          "url": "https://bugzilla.redhat.com/2480681"
        },
        {
          "url": "https://bugzilla.redhat.com/2480685"
        },
        {
          "url": "https://bugzilla.redhat.com/2480688"
        },
        {
          "url": "https://bugzilla.redhat.com/2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/2493620"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480680"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480681"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480685"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480688"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493620"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27136"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39829"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42508"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-57231"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-37123.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:37123"
        },
        {
          "url": "https://go.dev/cl/781641"
        },
        {
          "url": "https://go.dev/cl/781661"
        },
        {
          "url": "https://go.dev/issue/79565"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39829.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-37123.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5018"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39829.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39829"
        }
      ],
      "published": "2026-05-22T04:16:22+00:00",
      "updated": "2026-09-16T13:17:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-39830",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        119,
        772
      ],
      "description": "A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39830"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29455"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35833"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36199"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36207"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36625"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36808"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37072"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37268"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37271"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37272"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37275"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37278"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37296"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40969"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40972"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40974"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46885"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49944"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52857"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52910"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54400"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57801"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59467"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61314"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65964"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66521"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67450"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69961"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39830"
        },
        {
          "url": "https://bugzilla.redhat.com/2480684"
        },
        {
          "url": "https://bugzilla.redhat.com/2508234"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480684"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2518147"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-17106"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19730"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39830"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-69961.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69961"
        },
        {
          "url": "https://github.com/golang/crypto/commit/4e7a7384ecbc8d519f6f4c11b36fa9d761fc8946"
        },
        {
          "url": "https://go.dev/cl/781640"
        },
        {
          "url": "https://go.dev/cl/781664"
        },
        {
          "url": "https://go.dev/issue/79564"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39830.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69961.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5017"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39830.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39830"
        }
      ],
      "published": "2026-05-22T04:16:22+00:00",
      "updated": "2026-09-16T13:17:53+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-39831",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        862
      ],
      "description": "The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a \"no-touch-required\" extension in Permissions.Extensions from PublicKeyCallback.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39831"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39831"
        },
        {
          "url": "https://github.com/golang/crypto/commit/b61cf853a89d82cad68da5e12a6beca2116f8456"
        },
        {
          "url": "https://go.dev/cl/781662"
        },
        {
          "url": "https://go.dev/issue/79566"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5019"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39831"
        }
      ],
      "published": "2026-05-22T04:16:22+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-39832",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        502,
        281
      ],
      "description": "When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39832"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35833"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36199"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36625"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37072"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37123"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37271"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37410"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40972"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49944"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52857"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52910"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59579"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61314"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66521"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67450"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39832"
        },
        {
          "url": "https://bugzilla.redhat.com/2480680"
        },
        {
          "url": "https://bugzilla.redhat.com/2480685"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480680"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480685"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-37410.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:37410"
        },
        {
          "url": "https://github.com/golang/crypto/commit/e3d1254f1e7e60baa086142c46174bf6d8d0fe50"
        },
        {
          "url": "https://go.dev/cl/778640"
        },
        {
          "url": "https://go.dev/cl/778641"
        },
        {
          "url": "https://go.dev/cl/778642"
        },
        {
          "url": "https://go.dev/issue/79435"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39832.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-37410.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5006"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39832.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39832"
        }
      ],
      "published": "2026-05-22T04:16:22+00:00",
      "updated": "2026-09-15T12:17:40+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-39833",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        862
      ],
      "description": "The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39833"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39833"
        },
        {
          "url": "https://github.com/golang/crypto/commit/0fb843a472225645e917c84f1f9744757f0bab14"
        },
        {
          "url": "https://go.dev/cl/778640"
        },
        {
          "url": "https://go.dev/cl/778641"
        },
        {
          "url": "https://go.dev/cl/778642"
        },
        {
          "url": "https://go.dev/issue/79436"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5005"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39833"
        }
      ],
      "published": "2026-05-22T04:16:22+00:00",
      "updated": "2026-08-11T22:17:25+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-39834",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty packets without making progress. The size comparison now uses int64 to prevent truncation.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39834"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39834"
        },
        {
          "url": "https://github.com/golang/crypto/commit/e052873987615dc96fe67607a9a6adb76311344f"
        },
        {
          "url": "https://go.dev/cl/781663"
        },
        {
          "url": "https://go.dev/issue/79567"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5020"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39834"
        }
      ],
      "published": "2026-05-22T04:16:24+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-39835",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        295,
        476
      ],
      "description": "SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39835"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36199"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36207"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36625"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37072"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37123"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37268"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37271"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37272"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37296"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37410"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38504"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40969"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40972"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40974"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46885"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47949"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52857"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52910"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54525"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59467"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59593"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62260"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65126"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66521"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39835"
        },
        {
          "url": "https://bugzilla.redhat.com/2480680"
        },
        {
          "url": "https://bugzilla.redhat.com/2480685"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480680"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480685"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-37410.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:37410"
        },
        {
          "url": "https://go.dev/cl/781660"
        },
        {
          "url": "https://go.dev/issue/79563"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39835.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-38504.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5015"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39835.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39835"
        }
      ],
      "published": "2026-05-22T04:16:24+00:00",
      "updated": "2026-09-18T13:18:12+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-39836",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        476
      ],
      "description": "The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).",
      "recommendation": "Upgrade stdlib to version 1.25.10, 1.26.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39836"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22112"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22121"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39836"
        },
        {
          "url": "https://bugzilla.redhat.com/2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467810"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467811"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467813"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467823"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467825"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467826"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467827"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33814"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39817"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39819"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39823"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39825"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39826"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39836"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42501"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-22112.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:22121"
        },
        {
          "url": "https://go.dev/cl/775320"
        },
        {
          "url": "https://go.dev/issue/79006"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/qcCIEXso47M"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39836.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-22121.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39836"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4971"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39836"
        }
      ],
      "published": "2026-05-07T20:16:43+00:00",
      "updated": "2026-06-17T10:42:40+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-41506",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        522
      ],
      "description": "go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has been patched in versions 5.18.0 and 6.0.0-alpha.2.",
      "recommendation": "Upgrade github.com/go-git/go-git/v5 to version 5.18.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41506"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41506"
        },
        {
          "url": "https://github.com/go-git/go-git"
        },
        {
          "url": "https://github.com/go-git/go-git/releases/tag/v5.18.0"
        },
        {
          "url": "https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.2"
        },
        {
          "url": "https://github.com/go-git/go-git/security/advisories/GHSA-3xc5-wrhm-f963"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41506"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41506"
        }
      ],
      "published": "2026-05-08T14:16:33+00:00",
      "updated": "2026-06-17T10:46:48+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/go-git/go-git/v5@v5.12.0"
        }
      ]
    },
    {
      "id": "CVE-2026-41567",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        427
      ],
      "description": "Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41567"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41030"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42852"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44622"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51057"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41567"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2485356"
        },
        {
          "url": "https://github.com/moby/moby"
        },
        {
          "url": "https://github.com/moby/moby/security/advisories/GHSA-x86f-5xw2-fm2r"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41567"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41567.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41567"
        }
      ],
      "published": "2026-06-05T02:17:13+00:00",
      "updated": "2026-09-09T13:19:53+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible"
        }
      ]
    },
    {
      "id": "CVE-2026-41568",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L"
        }
      ],
      "cwes": [
        81,
        367
      ],
      "description": "Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on the host filesystem. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41568"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41568"
        },
        {
          "url": "https://github.com/moby/moby"
        },
        {
          "url": "https://github.com/moby/moby/security/advisories/GHSA-vp62-88p7-qqf5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41568"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41568"
        }
      ],
      "published": "2026-06-12T19:16:26+00:00",
      "updated": "2026-06-17T10:46:51+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible"
        }
      ]
    },
    {
      "id": "CVE-2026-42306",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H"
        }
      ],
      "cwes": [
        61,
        367
      ],
      "description": "Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path, potentially overwriting host files or causing denial of service. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42306"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42306"
        },
        {
          "url": "https://github.com/moby/moby"
        },
        {
          "url": "https://github.com/moby/moby/security/advisories/GHSA-rg2x-37c3-w2rh"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42306"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42306"
        }
      ],
      "published": "2026-06-12T19:16:27+00:00",
      "updated": "2026-06-17T10:47:39+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible",
          "versions": [
            {
              "version": "v27.1.1+incompatible",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/docker/docker@v27.1.1%2Bincompatible"
        }
      ]
    },
    {
      "id": "CVE-2026-42499",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        1046
      ],
      "description": "Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.",
      "recommendation": "Upgrade stdlib to version 1.25.10, 1.26.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42499"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17713"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:17714"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22112"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22120"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22121"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33120"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33123"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33142"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33574"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34364"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36625"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36754"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47952"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49702"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49712"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50300"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50336"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50843"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51112"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54274"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54283"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54284"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54285"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54552"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54555"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54583"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54602"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56340"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56785"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56789"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56852"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56854"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56910"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56912"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57482"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57487"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57649"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57845"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57914"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59467"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59830"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59833"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60023"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61253"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62260"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62406"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62407"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62753"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62754"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62803"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63163"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63332"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63636"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:64818"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65116"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65117"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65153"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65335"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65336"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65534"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65838"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65886"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65895"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66327"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67148"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67517"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67974"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67975"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:68334"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:68504"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:68527"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42499"
        },
        {
          "url": "https://bugzilla.redhat.com/2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/2484204"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456333"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456339"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484204"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515840"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-65153.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:65886"
        },
        {
          "url": "https://go.dev/cl/771520"
        },
        {
          "url": "https://go.dev/issue/78987"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/qcCIEXso47M"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42499.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70201.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4977"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42499"
        }
      ],
      "published": "2026-05-07T20:16:44+00:00",
      "updated": "2026-09-18T13:18:17+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42502",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        1021
      ],
      "description": "Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.",
      "recommendation": "Upgrade golang.org/x/net to version 0.55.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42502"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69293"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42502"
        },
        {
          "url": "https://bugzilla.redhat.com/2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/2480762"
        },
        {
          "url": "https://bugzilla.redhat.com/2484830"
        },
        {
          "url": "https://bugzilla.redhat.com/2493622"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480762"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484830"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493622"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27136"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41178"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55677"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-69293.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69293"
        },
        {
          "url": "https://go.dev/cl/781701"
        },
        {
          "url": "https://go.dev/issue/79572"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42502.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67139-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5027"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42502"
        }
      ],
      "published": "2026-05-22T16:16:20+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/net@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-42504",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        407
      ],
      "description": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.",
      "recommendation": "Upgrade stdlib to version 1.25.11, 1.26.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42504"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65153"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65886"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42504"
        },
        {
          "url": "https://bugzilla.redhat.com/2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/2484204"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456333"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456339"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484204"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515840"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-65153.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:65886"
        },
        {
          "url": "https://go.dev/cl/774481"
        },
        {
          "url": "https://go.dev/issue/79217"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42504.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69308.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5038"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42504"
        }
      ],
      "published": "2026-06-02T23:16:37+00:00",
      "updated": "2026-07-22T19:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42505",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        201
      ],
      "description": "Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.",
      "recommendation": "Upgrade stdlib to version 1.25.12, 1.26.5, 1.27.0-rc.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42505"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66364"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42505"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-66364.html"
        },
        {
          "url": "https://go.dev/cl/775960"
        },
        {
          "url": "https://go.dev/issue/79282"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5856"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42505"
        }
      ],
      "published": "2026-07-08T17:17:21+00:00",
      "updated": "2026-09-16T20:14:44+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the Go stdlib flaw is carried by a bundled Go binary (the Confluent CLI / tooling) in the image, not the product's Java runtime, so the vulnerable code path is not reachable in the product."
      }
    },
    {
      "id": "CVE-2026-42506",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        79
      ],
      "description": "Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.",
      "recommendation": "Upgrade golang.org/x/net to version 0.55.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42506"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42506"
        },
        {
          "url": "https://go.dev/cl/781700"
        },
        {
          "url": "https://go.dev/issue/79571"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5025"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42506"
        }
      ],
      "published": "2026-05-22T16:16:20+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/net@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-42507",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "description": "When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.",
      "recommendation": "Upgrade stdlib to version 1.25.11, 1.26.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42507"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66364"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42507"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484205"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484207"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42507"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-66364.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:29981"
        },
        {
          "url": "https://go.dev/cl/777060"
        },
        {
          "url": "https://go.dev/issue/79346"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42507.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-29981.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5039"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42507"
        }
      ],
      "published": "2026-06-02T23:16:38+00:00",
      "updated": "2026-07-22T19:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42508",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        295
      ],
      "description": "Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42508"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23264"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35833"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36808"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37072"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37123"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46885"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47737"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49944"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51288"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52857"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52910"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54400"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59467"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61314"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65126"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66521"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67450"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42508"
        },
        {
          "url": "https://bugzilla.redhat.com/2480680"
        },
        {
          "url": "https://bugzilla.redhat.com/2480681"
        },
        {
          "url": "https://bugzilla.redhat.com/2480685"
        },
        {
          "url": "https://bugzilla.redhat.com/2480688"
        },
        {
          "url": "https://bugzilla.redhat.com/2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/2493620"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480680"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480681"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480685"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480688"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493620"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27136"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39829"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42508"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-57231"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-37123.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:37123"
        },
        {
          "url": "https://github.com/golang/crypto/commit/f717e29698a271c548239ed56bf5dd9516d6f7e8"
        },
        {
          "url": "https://go.dev/cl/781220"
        },
        {
          "url": "https://go.dev/issue/79568"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42508.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-37123.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5021"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42508.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42508"
        }
      ],
      "published": "2026-05-22T04:16:25+00:00",
      "updated": "2026-09-15T12:17:45+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-44740",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        674,
        835
      ],
      "description": "Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.",
      "recommendation": "Upgrade github.com/go-git/go-billy/v5 to version 5.9.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44740"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46391"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44740"
        },
        {
          "url": "https://bugzilla.redhat.com/2483894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2483894"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44740"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-46391.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:46391"
        },
        {
          "url": "https://github.com/go-git/go-billy"
        },
        {
          "url": "https://github.com/go-git/go-billy/releases/tag/v5.9.0"
        },
        {
          "url": "https://github.com/go-git/go-billy/releases/tag/v6.0.0-alpha.1"
        },
        {
          "url": "https://github.com/go-git/go-billy/security/advisories/GHSA-m3xc-h892-ggx6"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-44740.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-46391.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44740"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44740"
        }
      ],
      "published": "2026-06-01T17:17:08+00:00",
      "updated": "2026-07-22T07:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/go-git/go-billy/v5@v5.5.0",
          "versions": [
            {
              "version": "v5.5.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-billy/v5@v5.5.0",
          "versions": [
            {
              "version": "v5.5.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-billy/v5@v5.5.0",
          "versions": [
            {
              "version": "v5.5.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-billy/v5@v5.5.0",
          "versions": [
            {
              "version": "v5.5.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-billy/v5@v5.5.0",
          "versions": [
            {
              "version": "v5.5.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/go-git/go-billy/v5@v5.5.0"
        }
      ]
    },
    {
      "id": "CVE-2026-44973",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        22
      ],
      "description": "Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient path sanitization and boundary enforcement may allow crafted paths (e.g., using ..) to escape intended base directories. While go-billy was not originally designed to provide a strong security boundary, some of these issues were inconsistent across some of the built-in implementations. This results in scenarios where applications relying on go-billy for some level of isolation may inadvertently expose access to unintended filesystem locations. This vulnerability is fixed in 5.9.0.",
      "recommendation": "Upgrade github.com/go-git/go-billy/v5 to version 5.9.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44973"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44973"
        },
        {
          "url": "https://github.com/go-git/go-billy"
        },
        {
          "url": "https://github.com/go-git/go-billy/releases/tag/v5.9.0"
        },
        {
          "url": "https://github.com/go-git/go-billy/releases/tag/v6.0.0-alpha.1"
        },
        {
          "url": "https://github.com/go-git/go-billy/security/advisories/GHSA-qw64-3x98-g7q2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44973"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44973"
        }
      ],
      "published": "2026-05-28T22:16:59+00:00",
      "updated": "2026-07-21T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/go-git/go-billy/v5@v5.5.0",
          "versions": [
            {
              "version": "v5.5.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-billy/v5@v5.5.0",
          "versions": [
            {
              "version": "v5.5.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-billy/v5@v5.5.0",
          "versions": [
            {
              "version": "v5.5.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-billy/v5@v5.5.0",
          "versions": [
            {
              "version": "v5.5.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-billy/v5@v5.5.0",
          "versions": [
            {
              "version": "v5.5.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/go-git/go-billy/v5@v5.5.0"
        }
      ]
    },
    {
      "id": "CVE-2026-45022",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        180,
        345
      ],
      "description": "go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit or tag objects contain ambiguous or malformed headers, go-git\u2019s decoded representation may expose values differently from how Git itself would interpret or reject the same object. Additionally, go-git\u2019s commit signing and verification logic operates over commit data reconstructed from go-git\u2019s parsed representation rather than the original raw object bytes. As a result, go-git may sign or verify a commit payload that is not byte-for-byte equivalent to the object stored in the repository. This can cause a signature to appear valid for a commit whose displayed or effective metadata differs from the object that was intended to be signed. This vulnerability is fixed in 5.19.0 and 6.0.0-alpha.3.",
      "recommendation": "Upgrade github.com/go-git/go-git/v5 to version 5.19.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45022"
        },
        {
          "url": "https://github.com/go-git/go-git"
        },
        {
          "url": "https://github.com/go-git/go-git/security/advisories/GHSA-389r-gv7p-r3rp"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45022"
        }
      ],
      "published": "2026-05-27T15:16:29+00:00",
      "updated": "2026-06-17T10:51:36+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/go-git/go-git/v5@v5.12.0"
        }
      ]
    },
    {
      "id": "CVE-2026-45570",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.6,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        116
      ],
      "description": "go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping single quotes embedded inside the path. A repository path containing a single quote can therefore break out of the quoted region in the exec command and be appended as additional shell tokens. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4.",
      "recommendation": "Upgrade github.com/go-git/go-git/v5 to version 5.19.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45570"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-45570"
        },
        {
          "url": "https://github.com/go-git/go-git"
        },
        {
          "url": "https://github.com/go-git/go-git/security/advisories/GHSA-m7cr-m3pv-hgrp"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45570"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45570"
        }
      ],
      "published": "2026-05-27T15:16:30+00:00",
      "updated": "2026-06-17T10:52:13+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/go-git/go-git/v5@v5.12.0"
        }
      ]
    },
    {
      "id": "CVE-2026-45571",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        22
      ],
      "description": "go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory. These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from those checks. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4.",
      "recommendation": "Upgrade github.com/go-git/go-git/v5 to version 5.19.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45571"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-45571"
        },
        {
          "url": "https://github.com/go-git/go-git"
        },
        {
          "url": "https://github.com/go-git/go-git/security/advisories/GHSA-crhj-59gh-8x96"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45571"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45571"
        }
      ],
      "published": "2026-05-27T15:16:30+00:00",
      "updated": "2026-06-17T10:52:13+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/go-git/go-git/v5@v5.12.0"
        }
      ]
    },
    {
      "id": "CVE-2026-46595",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        863,
        303
      ],
      "description": "Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-46595"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23264"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30650"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33524"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36207"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36808"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37275"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47737"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59467"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59558"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61314"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66521"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-46595"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480689"
        },
        {
          "url": "https://github.com/golang/crypto/commit/533fb3f7e4a5ae23f69d1837cd851d35ff5b76ce"
        },
        {
          "url": "https://go.dev/cl/781642"
        },
        {
          "url": "https://go.dev/issue/79570"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5023"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46595.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46595"
        }
      ],
      "published": "2026-05-22T04:16:25+00:00",
      "updated": "2026-09-11T13:18:12+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-46597",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        704
      ],
      "description": "An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-46597"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-46597"
        },
        {
          "url": "https://go.dev/cl/781620"
        },
        {
          "url": "https://go.dev/issue/79561"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5013"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46597"
        }
      ],
      "published": "2026-05-22T04:16:26+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-46598",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        129
      ],
      "description": "For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-46598"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-46598"
        },
        {
          "url": "https://go.dev/cl/781360"
        },
        {
          "url": "https://go.dev/issue/79596"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5033"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46598"
        }
      ],
      "published": "2026-05-22T04:16:26+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-46600",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.",
      "recommendation": "Upgrade golang.org/x/net to version 0.56.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-46600"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-46600"
        },
        {
          "url": "https://go.dev/cl/786345"
        },
        {
          "url": "https://go.dev/issue/79795"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5942"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46600"
        }
      ],
      "published": "2026-07-21T20:17:01+00:00",
      "updated": "2026-08-14T16:16:55+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/net@v0.25.0"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-56851",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "cwes": [
        787
      ],
      "description": "The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer.",
      "recommendation": "Upgrade golang.org/x/text to version 0.41.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56851"
        },
        {
          "url": "https://go.dev/cl/793360"
        },
        {
          "url": "https://go.dev/issue/80112"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6629"
        }
      ],
      "published": "2026-10-07T18:17:20+00:00",
      "updated": "2026-10-08T21:35:53+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/text@v0.16.0",
          "versions": [
            {
              "version": "v0.16.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.16.0",
          "versions": [
            {
              "version": "v0.16.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.16.0",
          "versions": [
            {
              "version": "v0.16.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.16.0",
          "versions": [
            {
              "version": "v0.16.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.16.0",
          "versions": [
            {
              "version": "v0.16.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/text@v0.16.0"
        }
      ]
    },
    {
      "id": "CVE-2026-56852",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        835
      ],
      "description": "A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.",
      "recommendation": "Upgrade golang.org/x/text to version 0.39.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56852"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70201"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56852"
        },
        {
          "url": "https://bugzilla.redhat.com/2456335"
        },
        {
          "url": "https://bugzilla.redhat.com/2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/2504233"
        },
        {
          "url": "https://bugzilla.redhat.com/2508234"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456335"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2504233"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2518147"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-17106"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19730"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33810"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56852"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-70201.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70201"
        },
        {
          "url": "https://go.dev/cl/794100"
        },
        {
          "url": "https://go.dev/issue/80142"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56852.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70201.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5970"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56852"
        }
      ],
      "published": "2026-07-21T20:17:02+00:00",
      "updated": "2026-07-23T18:27:48+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/text@v0.16.0",
          "versions": [
            {
              "version": "v0.16.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.16.0",
          "versions": [
            {
              "version": "v0.16.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.16.0",
          "versions": [
            {
              "version": "v0.16.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.16.0",
          "versions": [
            {
              "version": "v0.16.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.16.0",
          "versions": [
            {
              "version": "v0.16.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/text@v0.16.0"
        }
      ]
    },
    {
      "id": "CVE-2026-56853",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        770
      ],
      "description": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56853"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70641"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56853"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11395"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-70641.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70641"
        },
        {
          "url": "https://go.dev/cl/795540"
        },
        {
          "url": "https://go.dev/issue/80205"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56853.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6089"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56853"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56854",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        863
      ],
      "description": "The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.55.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56854"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56854"
        },
        {
          "url": "https://go.dev/cl/797040"
        },
        {
          "url": "https://go.dev/issue/80213"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6303"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56854"
        }
      ],
      "published": "2026-08-28T16:18:17+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-56855",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.56.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56855"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70640"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56855"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503742"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528050"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11395"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15789"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56855"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-70640.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70640"
        },
        {
          "url": "https://go.dev/cl/826524"
        },
        {
          "url": "https://go.dev/issue/81317"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/1y3fb2np35U"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56855.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70640.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6355"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56855"
        }
      ],
      "published": "2026-09-02T20:17:36+00:00",
      "updated": "2026-09-04T16:34:56+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "CVE-2026-56858",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        79
      ],
      "description": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56858"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70641"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56858"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11395"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-70641.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70641"
        },
        {
          "url": "https://go.dev/cl/807100"
        },
        {
          "url": "https://go.dev/issue/80435"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56858.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6091"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56858"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56859",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56859"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69961"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56859"
        },
        {
          "url": "https://bugzilla.redhat.com/2480684"
        },
        {
          "url": "https://bugzilla.redhat.com/2508234"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480684"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2518147"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-17106"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19730"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39830"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-69961.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69961"
        },
        {
          "url": "https://go.dev/cl/803320"
        },
        {
          "url": "https://go.dev/issue/80481"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56859.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70201.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6088"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56859"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56860",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        407
      ],
      "description": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56860"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70641"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56860"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11395"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-70641.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70641"
        },
        {
          "url": "https://go.dev/cl/803681"
        },
        {
          "url": "https://go.dev/issue/80494"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56860.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6218"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56860"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56862",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56862"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70641"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56862"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11395"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-70641.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70641"
        },
        {
          "url": "https://go.dev/cl/804261"
        },
        {
          "url": "https://go.dev/issue/80528"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56862.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6090"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56862"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.22.7",
          "versions": [
            {
              "version": "v1.22.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/stdlib@v1.22.7"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-71556",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L"
        }
      ],
      "cwes": [
        59
      ],
      "description": "go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5.",
      "recommendation": "Upgrade github.com/go-git/go-git/v5 to version 5.19.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-71556"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-71556"
        },
        {
          "url": "https://github.com/go-git/go-git"
        },
        {
          "url": "https://github.com/go-git/go-git/commit/008a78f2dd86f52544ddff8b8e8ddeecdf3f7aab"
        },
        {
          "url": "https://github.com/go-git/go-git/commit/661d1c7f101d34e002a3cfcf8dbea5b7421d07ac"
        },
        {
          "url": "https://github.com/go-git/go-git/releases/tag/v5.19.2"
        },
        {
          "url": "https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.5"
        },
        {
          "url": "https://github.com/go-git/go-git/security/advisories/GHSA-hc8v-wwc9-vgxm"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71556"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-71556"
        }
      ],
      "published": "2026-08-07T17:17:10+00:00",
      "updated": "2026-09-10T20:41:33+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/go-git/go-git/v5@v5.12.0"
        }
      ]
    },
    {
      "id": "CVE-2026-71557",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L"
        }
      ],
      "cwes": [
        22
      ],
      "description": "go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences) can cause go-git to write files outside the intended reference storage directory. Versions 5.19.2 and 6.0.0-alpha.5 fix the issue.",
      "recommendation": "Upgrade github.com/go-git/go-git/v5 to version 5.19.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-71557"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-71557"
        },
        {
          "url": "https://github.com/go-git/go-git"
        },
        {
          "url": "https://github.com/go-git/go-git/commit/4a0e66d555de5f9a30c31e2df64f445f42bd01e7"
        },
        {
          "url": "https://github.com/go-git/go-git/commit/da9f7d8a0e98b475600177348d6ece384a370f36"
        },
        {
          "url": "https://github.com/go-git/go-git/pull/2247"
        },
        {
          "url": "https://github.com/go-git/go-git/pull/2254"
        },
        {
          "url": "https://github.com/go-git/go-git/releases/tag/v5.19.2"
        },
        {
          "url": "https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.5"
        },
        {
          "url": "https://github.com/go-git/go-git/security/advisories/GHSA-qgq7-7hm3-q39j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71557"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-71557"
        }
      ],
      "published": "2026-08-07T17:17:10+00:00",
      "updated": "2026-09-10T20:41:33+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/go-git/go-git/v5@v5.12.0"
        }
      ]
    },
    {
      "id": "CVE-2026-78662",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.56.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78662"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-78662"
        },
        {
          "url": "https://go.dev/cl/826504"
        },
        {
          "url": "https://go.dev/issue/81316"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/1y3fb2np35U"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6354"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78662"
        }
      ],
      "published": "2026-09-02T20:17:37+00:00",
      "updated": "2026-09-04T16:33:34+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    },
    {
      "id": "GHSA-w5pp-99ch-qj29",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "description": "### Impact\nSeveral denial-of-service issues were identified in `go-git` when parsing maliciously crafted Git repository data.\n\nAn attacker may craft a malicious `.pack`, `.idx` or loose objects that causes an application using an affected version of `go-git` to panic or consume excessive resources.\n\nThis can lead to denial of service in applications that use `go-git` to clone, fetch, open, or otherwise process untrusted repositories or Git object data.\n\nExploitation requires the ability to alter read-only files such as `.pack` or `.idx` from the local repository's `.git/objects/pack/` directory. Alternatively, the user would need to be interacting with a malicious remote server, which is not recommended and exposes users to a broader class of security risks beyond this issue.\n\n### Patches\nUsers should upgrade to a patched version in order to mitigate this vulnerability. Versions prior to `v5` are likely to be affected, users are recommended to upgrade to a supported `go-git` version.\n\n### Credits\ngo-git thanks @kodareef5, @AyushParkara and @N0zoM1z0 for reporting this in four separate reports. \ud83d\ude47",
      "recommendation": "Upgrade github.com/go-git/go-git/v5 to version 5.19.1",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-w5pp-99ch-qj29"
        },
        {
          "url": "https://github.com/go-git/go-git"
        },
        {
          "url": "https://github.com/go-git/go-git/security/advisories/GHSA-w5pp-99ch-qj29"
        }
      ],
      "published": "2026-05-29T19:43:27+00:00",
      "updated": "2026-05-29T19:43:27+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.12.0",
          "versions": [
            {
              "version": "v5.12.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/github.com/go-git/go-git/v5@v5.12.0"
        }
      ]
    },
    {
      "id": "GO-2026-5932",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used.\n\nIf you are required to interoperate with OpenPGP systems and need a maintained package, consider github.com/ProtonMail/go-crypto/openpgp which is a maintained fork that aims to be a drop-in replacement for this package.",
      "advisories": [
        {
          "url": "https://go.dev/issue/44226"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5932"
        }
      ],
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.25.0",
          "versions": [
            {
              "version": "v0.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:78665e49-edb2-439e-852d-680158fc5efa/1#pkg:golang/golang.org/x/crypto@v0.25.0"
        }
      ]
    }
  ]
}